10/26/2025
I’ve got something worrying to point out: Even trusted tools can be hijacked ⚠️
Gravity Forms, a hugely popular WordPress plugin with over a million users, was briefly compromised in what’s known as a supply chain attack.
Here’s what happened:
☠️ Attackers managed to sneak malicious files into certain manual downloads of the plugin from Gravity Forms’ own website
☠️ Those files could block updates, create hidden admin accounts, and even allow remote code ex*****on (basically, full control over a site)
☠️ The affected versions were only live for a short window in early July, but anyone who grabbed those versions manually was at risk
The good news?
• Automatic updates and installations done from inside the plugin itself were never affected
• The company, RocketGenius, acted quickly, closed off the attack method, and has already released a clean version (2.9.13)
• They’ve reached out directly to anyone who might have been exposed
But this is still an important reminder:
🔒 Even legitimate, well‑known tools can be targeted
🔒 Always keep plugins updated directly through their official update mechanisms wherever possible
🔒 If you manually download any software, double‑check you’re on the official site and confirm the version number you’re installing
Stories like this highlight how important it is to stay aware of the risks. A single compromised plugin can open the door to attackers. And that can mean stolen data, downtime, or worse.
❓Do you (or your team) ever manually install plugins? Or do you rely on automatic updates?