The Gravity Forms WordPress Plugin Supply Chain Attack

Updated 5 Oct 2026 · Incident date 9 Jul 2025 · other

PackageGravity Forms 2.9.11.1 and 2.9.12 manual installers from gravityforms.com; fixed in 2.9.13
Filecommon.php

In July 2025, attackers changed the Gravity Forms plugin files on the official gravityforms.com download page. Versions 2.9.11.1 and 2.9.12 carried a backdoor. The fixed version is 2.9.13.

Only manual downloads and Composer installs were affected. Auto-updates and the Gravity API service were not compromised, according to SecurityWeek.

What happened

Attackers added malicious code to the plugin package that the official site served. Patchstack reports that the attacker registered the domain gravityapi.org on 8 July 2025. People downloaded the bad plugin on 9 and 10 July. Patchstack received reports on 11 July, and RocketGenius released 2.9.13 the same day.

Patchstack found the code in gravityforms/common.php and includes/settings/class-settings.php. It ran whenever the plugin was active, and it did two things:

A second backdoor accepted requests with a secret token. With it, an attacker can create administrator accounts, run PHP code, upload files and list or delete users. BleepingComputer adds that the code blocked update attempts.

Patchstack states that the infection did not seem widespread. BleepingComputer and SecurityWeek put the plugin at about one million sites in total. Only sites that took the bad packages in the window were exposed.

Vigilance compares the version you trust with the new one. It reports the file that gained a new capability. A plugin that starts calling an outside domain is the kind of change it shows. See the scan block below.

Affected versions

Installs from the WordPress.org repository were not affected, according to Patchstack.

Indicators of compromise

How to check

Search the plugin folder and wp-includes for the domain and the dropped files. Run this in the WordPress root.

grep -rIl "gravityapi" wp-content/plugins/gravityforms; ls -l wp-includes/bookmark-canonical.php wp-includes/block-caching.php

Then check the version with WP-CLI.

wp plugin get gravityforms --field=version

A version of 2.9.13 or later does not prove a clean site. A site that ran a bad version can still hold the dropped file. Also list administrator accounts with wp user list --role=administrator.

What to do now

  1. Update Gravity Forms to 2.9.13 or later from a trusted source.
  2. Delete the dropped files in wp-includes if they exist.
  3. Remove administrator accounts that you do not recognize.
  4. Change all administrator, database and hosting passwords. Rotate the WordPress salts.
  5. Block the domains and IP addresses above.
  6. If you find the backdoor, restore the site from a backup made before 9 July 2025 or rebuild it.

What Vigilance showed

Vigilance compares the version you trust with the new one and names the file that gained a new capability. The block below is rebuilt from the public reports in the words Vigilance prints. It is not a captured scan, because the malicious release is not redistributed.

vigi diff --old Gravity-prev --new Gravity-current
files scanned: 64

HEADS UP  1 file can now do things the old version could not. The rest changed and gained nothing.

CHANGED    common.php
           It now downloads from the internet, runs other programs and runs a hidden, encoded command. It did not before.

Frequently asked questions

Which Gravity Forms versions were compromised?

Versions 2.9.11.1 and 2.9.12 from the official gravityforms.com download page were compromised in July 2025. Version 2.9.13 removed the malicious code.

Did the Gravity Forms attack affect automatic updates?

No. SecurityWeek reports that the auto-update mechanism and the Gravity API service were not compromised. Only manual downloads and Composer installs were affected.

Sources

  1. patchstack.com/articles/critical-malware-found-in-gravityforms-official-plugin-site/
  2. bleepingcomputer.com/news/security/wordpress-gravity-forms-developer-hacked-to-push-backdoored-plugins/
  3. securityweek.com/hackers-inject-malware-into-gravity-forms-wordpress-plugin/

More supply chain attacks

All 111 attacks in the library · What is a supply chain attack? · How to prevent supply chain attacks

Check the next update before you install it

Vigilance compares the version you trust with the new one. It names the one file that can now do something it could not do before.

Start Free