Open Source · · 3 days

Contact Form 7 addon created backdoors

Malicious code was injected directly into the Contact Form 7 Multi-Step Addon plugin repository on WordPress.org.

Part of WordPress.org plugins created admin backdoors campaign

Contact Form 7 Multi-Step Addon was part of the same June 2024 WordPress.org plugin campaign. The compromise sat in the official plugin repository, so normal update behavior delivered the malicious code.

Wordfence identified versions 1.0.4 and 1.0.5 as infected and reported no patched version when it published. The correct response was removal or replacement until a safe release existed.

The shared malware tried to create new administrator users and report credentials to 94.156.79.8. It also placed SEO-spam JavaScript in the site footer, giving the attacker persistence and monetization from the same plugin update.

This record captures the Contact Form 7 add-on artifact, not the whole campaign. The package-level boundary matters because site owners had to search for this specific slug and infected version pair, not merely for any WordPress compromise.

Appendix · Affected releases

contact-form-7-multi-step-addon wordpress fixed 1.0.7
1.0.4 sha256 65a7fe40…f3cf70db download unavailable
1.0.5 sha256 544d1888…80a34a4e download unavailable
  • Immutable SVN revision 3106373 is the first observed malicious source state and declares version 1.0.4. Revision 3071742 is the preceding clean file, revision 3106511 is malicious 1.0.5, and revision 3106787 is clean version 1.0.7.

Indicators

  • file_sha256contact-form-7-multi-step-addon-r3106373-trx-contact-form-7-multi-step-addon.php 65a7fe40bdc2b8c2777a3491388549dc11f1ffa23a29d0183eb5afa5f3cf70db
  • file_sha256contact-form-7-multi-step-addon-r3106511-trx-contact-form-7-multi-step-addon.php 544d18888e67106a00adf9eb4a8fce64dc8e05775f9124a9c091dc8f80a34a4e

References

  1. Supply Chain Attack on WordPress.org Plugins Leads to 5 Maliciously Compromised WordPress Pluginswordfence.com
  2. CVE-2024-6297 recordcveawg.mitre.org
  3. Various Plugins - Injected Backdoorwpscan.com

Source record: oss/attacks/wp-contact-form-7-multi-step/meta.yaml