Description: Gravity Forms is an easy-to-use WordPress forms builder that has over 1 million active installations. For a limited time and only via specific methods, two Gravity Forms core plugin packages (2.9.11.1 and 2.9.12) offered for manual download were compromised by an external agent who made unauthorized code modifications. The attacker inserted malicious code into the plugin packages, which blocks update attempts, contacts an external server to download additional payloads, and attempts to create a new admin account, opening a backdoor for further exploitation.
Affected Versions :
Gravity Forms 2.9.11.1 (manually downloaded on July 9-10, 2025)
Gravity Forms 2.9.12 (manually downloaded on July 10, 2025)
Impact:
Successful exploitation allows full control of the affected WordPress site.
Resolution:
Update immediately to Gravity Forms 2.9.13 or later.