A significant and sustained exploitation campaign is currently targeting WordPress websites, capitalising on three critical, yet long-patched, security flaws within two widely used plugins: GutenKit and Hunk Companion. The sheer scale of this offensive serves as a stark reminder of the enduring threat posed by unpatched vulnerabilities in the digital realm.
The Alarming Scope of the Attack
The campaign, which saw a marked resurgence around October 8th and 9th of the current year (2025), prompted an immediate response from cybersecurity experts. Wordfence, a leading WordPress security firm, reported blocking a staggering 8.7 million attack attempts against its protected clientele over just those two days, underscoring the aggressive and automated nature of the threat actors involved. This recent surge follows earlier large-scale exploitation incidents targeting the very same flaws, indicating a persistent, cyclical pattern of attacks.
Anatomy of the Flaws: Critical Security Gaps
The exploitation campaign leverages three vulnerabilities, all assigned the maximum severity score of CVSS 9.8 (Critical):
-
CVE-2024-9234 (GutenKit): This flaw affects GutenKit versions 2.1.0 and earlier, a plugin with over 40,000 active installations. It is an unauthenticated REST-endpoint flaw that, due to a missing capability check, allows an attacker to install and activate arbitrary plugins or upload files masquerading as plugins without any form of authentication.
-
CVE-2024-9707 and CVE-2024-11972 (Hunk Companion): These two flaws impact the Hunk Companion plugin (with over 8,000 installations) in versions 1.8.4 and older, and 1.8.5 and previous versions, respectively. They are both missing-authorization vulnerabilities in the plugin's REST API endpoint (
themehunk-import), which an unauthenticated attacker can exploit to install and activate arbitrary plugins. CVE-2024-11972 is noted as a patch bypass for the earlier CVE-2024-9707.
The common denominator is the ability for an attacker to remotely install a plugin, an action that paves the way for a worst-case scenario: Remote Code Execution (RCE), ultimately leading to complete site takeover.
The Malicious Payload and Execution
Once arbitrary plugin installation is possible, the threat actors execute a sophisticated, multi-stage attack:
-
Malicious Plugin Installation: The attackers fetch a malicious .ZIP archive (often referred to as 'up') hosted on platforms like GitHub and install it as a plugin. This archive contains obfuscated scripts that serve as backdoors.
-
Backdoor Functionality: These scripts are designed to grant persistent access, enabling the upload, download, and deletion of files, as well as the modification of file permissions. A particularly insidious component, disguised as part of the All in One SEO plugin and protected by a password, is used to automatically log the attacker in as an administrator.
-
RCE Fallback: When a direct administrator backdoor isn't immediately attainable, the attackers frequently pivot to installing another known-vulnerable plugin, such as 'wp-query-console', which possesses its own RCE flaw that can be leveraged without authentication, thus providing an alternative route to full compromise.
This malicious toolkit allows the perpetrators to maintain control, exfiltrate data, execute commands, and sniff private site data, inflicting maximum damage.
Mitigation and Indicators of Compromise
The troubling reality is that fixes for these vulnerabilities have been available for a significant period: GutenKit was patched in version 2.1.1 (released October 2024), and Hunk Companion in version 1.9.0 (released December 2024). The exploitation campaign thrives solely on the widespread failure of site administrators to apply these updates, making immediate patching the paramount defense.
Administrators are strongly advised to audit their systems and logs for the following Indicators of Compromise (IoCs):
-
Log Activity: Look for suspicious requests to the vulnerable REST endpoints:
-
/wp-json/gutenkit/v1/install-active-plugin -
/wp-json/hc/v1/themehunk-import
-
-
Malicious Files/Directories: Inspect the
/wp-content/pluginsand/wp-content/upgradedirectories for unknown or suspicious folders, especially those with names like/upor/wp-query-console.
Comparison of Current CMS Security Threats
1. The Critical WordPress Plugin Campaign: Millions of Attacks Blocked
In October 2025, WordPress faced a massive and sustained exploitation campaign, with security firms blocking nearly 9 million exploit attempts in a short period. This campaign targeted three critical vulnerabilities (CVE-2024-9234, CVE-2024-9707, and CVE-2024-11972) in two specific, though popular, third-party plugins: GutenKit and Hunk Companion.
| WordPress Attack Summary | Details |
| Vulnerability Type | Unauthenticated Arbitrary Plugin Installation/File Upload. The flaws stem from missing capability checks on REST API endpoints. |
| Impact | Remote Code Execution (RCE). Attackers can install a malicious ZIP file masquerading as a plugin, granting them administrator access, full site takeover, backdoors, and file management capabilities. |
| Scale | Mass Exploitation. Security vendors have blocked over 8.7 million exploit attempts, indicating a highly automated, widespread scanning and attack effort. |
| Remediation | Users must update to GutenKit version 2.1.1 and Hunk Companion version 1.9.0 or higher immediately. |
2. Joomla 5: Targeted Vulnerabilities vs. Mass Campaigns
While Joomla 5 is not immune to critical security flaws, the current threat landscape does not show a similar widespread, unauthenticated mass exploitation campaign at the scale seen in WordPress. Instead, Joomla's recent high-severity patches address authenticated RCE vectors and critical core flaws:
| Joomla 5 Security Summary | Details |
| Core RCE Vector | Malicious File Uploads via Media Manager (CVE-2025-22213). This RCE requires an authenticated user with "edit" privileges (e.g., an Editor or higher role), a higher barrier than the unauthenticated WordPress flaws. |
| XSS-to-RCE Risk | Cross-Site Scripting (XSS) flaws in the core filter component (CVE-2024-21726) could be leveraged to achieve RCE, but only by tricking an administrator into clicking a malicious link (requiring user interaction). |
| Extension Risk | Joomla still faces authenticated RCE and SQL Injection risks in specific, unpatched third-party extensions, emphasizing that the largest CMS security threat often lies in add-on components, not the core. |
| Remediation | Users must ensure they are on the latest versions, such as Joomla 5.3.4 or later, and apply all updates to third-party extensions immediately. |
Conclusion: A Tale of Two CMS Risks
The difference in the observed attacks highlights the security challenges of each platform:
-
WordPress's Risk: Its massive market share and sprawling third-party plugin ecosystem make it a constant target for automated, non-discriminatory mass attacks that exploit unauthenticated flaws to gain initial access.
-
Joomla's Risk: While it has a generally stronger built-in user access control system, vulnerabilities still exist in its core and extensions, often requiring an authenticated user or an attack chain involving user interaction (like an administrator clicking a link) to achieve the most critical results, like RCE.
All site administrators are urged to prioritize security patches, especially for third-party add-ons, regardless of the CMS platform.
Website development resources recomended by StormWarning!
Should you still be wanting to have a secure corporate website built for you please use one of these recomended resources:
-
Plum Systems
- We build beautiful professional websites that clearly represent the clients brand and mission. More importantly, the websites and web portals we design offer full interactive business support solutions making them so much more than just a web brochure. The web presences we create actively solve system and process issues and increase business automation.
- Contact Plum Systems
-
DEVTEQ
- Discover top-notch, affordable website hosting services that combine reliability, speed, and exceptional support.
Our hosting solutions cater to all your needs with robust features, seamless performance, and unbeatable prices.
Experience unparalleled uptime, easy scalability, and 24/7 customer support with our cost-effective hosting plans. Get your website online effortlessly and affordably with our premium hosting services. - Contact DEVTEQ
- Discover top-notch, affordable website hosting services that combine reliability, speed, and exceptional support.
-
WebExpert
- We specialise in creating affordable, powerful websites exclusively using well known platforms renowned for their robust security, built-in advanced features like sophisticated user access controls and multilingual support, and exceptional scalability. We offer professional results without the premium price tag by leveraging open-source efficiency, allowing your budget to deliver more power and functionality than simple website builders. Choose WebExpert to get a fast, secure, and feature-rich online presence built by dedicated platform specialists, ensuring your business has a superior foundation for future growth.
- Contact WebExpert