Open Source · · 3 days
Contact Form 7 addon created backdoors
Malicious code was injected directly into the Contact Form 7 Multi-Step Addon plugin repository on WordPress.org.
Part of WordPress.org plugins created admin backdoors campaign
Contact Form 7 Multi-Step Addon was part of the same June 2024 WordPress.org plugin campaign. The compromise sat in the official plugin repository, so normal update behavior delivered the malicious code.
Wordfence identified versions 1.0.4 and 1.0.5 as infected and reported no patched version when it published. The correct response was removal or replacement until a safe release existed.
The shared malware tried to create new administrator users and report credentials to 94.156.79.8. It also placed SEO-spam JavaScript in the site footer, giving the attacker persistence and monetization from the same plugin update.
This record captures the Contact Form 7 add-on artifact, not the whole campaign. The package-level boundary matters because site owners had to search for this specific slug and infected version pair, not merely for any WordPress compromise.
Appendix · Affected releases
- Immutable SVN revision 3106373 is the first observed malicious source state and declares version 1.0.4. Revision 3071742 is the preceding clean file, revision 3106511 is malicious 1.0.5, and revision 3106787 is clean version 1.0.7.
Indicators
- file_sha256contact-form-7-multi-step-addon-r3106373-trx-contact-form-7-multi-step-addon.php 65a7fe40bdc2b8c2777a3491388549dc11f1ffa23a29d0183eb5afa5f3cf70db
- file_sha256contact-form-7-multi-step-addon-r3106511-trx-contact-form-7-multi-step-addon.php 544d18888e67106a00adf9eb4a8fce64dc8e05775f9124a9c091dc8f80a34a4e
References
- Supply Chain Attack on WordPress.org Plugins Leads to 5 Maliciously Compromised WordPress Pluginswordfence.com
- CVE-2024-6297 recordcveawg.mitre.org
- Various Plugins - Injected Backdoorwpscan.com
Source record: oss/attacks/wp-contact-form-7-multi-step/meta.yaml