July 2025 supply-chain attack on the plugin.
Specific Gravity Forms releases shipped with malicious code that allowed remote code execution and unauthorized admin account creation. Wordfence and Search Engine Journal both covered the incident. Formester is a hosted SaaS, so a vulnerable build cannot be your problem.
Search Engine Journal and Wordfence advisories, July 2025.


