Mass RCE Attack on WordPress Plugins vs. Joomla 5 Security Landscape

Mass RCE Attack on WordPress Plugins vs. Joomla 5 Security Landscape

A significant and sustained exploitation campaign is currently targeting WordPress websites, capitalising on three critical, yet long-patched, security flaws within two widely used plugins: GutenKit and Hunk Companion. The sheer scale of this offensive serves as a stark reminder of the enduring threat posed by unpatched vulnerabilities in the digital realm.


The Alarming Scope of the Attack

The campaign, which saw a marked resurgence around October 8th and 9th of the current year (2025), prompted an immediate response from cybersecurity experts. Wordfence, a leading WordPress security firm, reported blocking a staggering 8.7 million attack attempts against its protected clientele over just those two days, underscoring the aggressive and automated nature of the threat actors involved. This recent surge follows earlier large-scale exploitation incidents targeting the very same flaws, indicating a persistent, cyclical pattern of attacks.


Anatomy of the Flaws: Critical Security Gaps

The exploitation campaign leverages three vulnerabilities, all assigned the maximum severity score of CVSS 9.8 (Critical):

  • CVE-2024-9234 (GutenKit): This flaw affects GutenKit versions 2.1.0 and earlier, a plugin with over 40,000 active installations. It is an unauthenticated REST-endpoint flaw that, due to a missing capability check, allows an attacker to install and activate arbitrary plugins or upload files masquerading as plugins without any form of authentication.

  • CVE-2024-9707 and CVE-2024-11972 (Hunk Companion): These two flaws impact the Hunk Companion plugin (with over 8,000 installations) in versions 1.8.4 and older, and 1.8.5 and previous versions, respectively. They are both missing-authorization vulnerabilities in the plugin's REST API endpoint (themehunk-import), which an unauthenticated attacker can exploit to install and activate arbitrary plugins. CVE-2024-11972 is noted as a patch bypass for the earlier CVE-2024-9707.

The common denominator is the ability for an attacker to remotely install a plugin, an action that paves the way for a worst-case scenario: Remote Code Execution (RCE), ultimately leading to complete site takeover.


The Malicious Payload and Execution

Once arbitrary plugin installation is possible, the threat actors execute a sophisticated, multi-stage attack:

  1. Malicious Plugin Installation: The attackers fetch a malicious .ZIP archive (often referred to as 'up') hosted on platforms like GitHub and install it as a plugin. This archive contains obfuscated scripts that serve as backdoors.

  2. Backdoor Functionality: These scripts are designed to grant persistent access, enabling the upload, download, and deletion of files, as well as the modification of file permissions. A particularly insidious component, disguised as part of the All in One SEO plugin and protected by a password, is used to automatically log the attacker in as an administrator.

  3. RCE Fallback: When a direct administrator backdoor isn't immediately attainable, the attackers frequently pivot to installing another known-vulnerable plugin, such as 'wp-query-console', which possesses its own RCE flaw that can be leveraged without authentication, thus providing an alternative route to full compromise.

This malicious toolkit allows the perpetrators to maintain control, exfiltrate data, execute commands, and sniff private site data, inflicting maximum damage.


Mitigation and Indicators of Compromise

The troubling reality is that fixes for these vulnerabilities have been available for a significant period: GutenKit was patched in version 2.1.1 (released October 2024), and Hunk Companion in version 1.9.0 (released December 2024). The exploitation campaign thrives solely on the widespread failure of site administrators to apply these updates, making immediate patching the paramount defense.

Administrators are strongly advised to audit their systems and logs for the following Indicators of Compromise (IoCs):

  • Log Activity: Look for suspicious requests to the vulnerable REST endpoints:

    • /wp-json/gutenkit/v1/install-active-plugin

    • /wp-json/hc/v1/themehunk-import

  • Malicious Files/Directories: Inspect the /wp-content/plugins and /wp-content/upgrade directories for unknown or suspicious folders, especially those with names like /up or /wp-query-console.

 

Comparison of Current CMS Security Threats

1. The Critical WordPress Plugin Campaign: Millions of Attacks Blocked

In October 2025, WordPress faced a massive and sustained exploitation campaign, with security firms blocking nearly 9 million exploit attempts in a short period. This campaign targeted three critical vulnerabilities (CVE-2024-9234, CVE-2024-9707, and CVE-2024-11972) in two specific, though popular, third-party plugins: GutenKit and Hunk Companion.

WordPress Attack Summary Details
Vulnerability Type Unauthenticated Arbitrary Plugin Installation/File Upload. The flaws stem from missing capability checks on REST API endpoints.
Impact Remote Code Execution (RCE). Attackers can install a malicious ZIP file masquerading as a plugin, granting them administrator access, full site takeover, backdoors, and file management capabilities.
Scale Mass Exploitation. Security vendors have blocked over 8.7 million exploit attempts, indicating a highly automated, widespread scanning and attack effort.
Remediation Users must update to GutenKit version 2.1.1 and Hunk Companion version 1.9.0 or higher immediately.

2. Joomla 5: Targeted Vulnerabilities vs. Mass Campaigns

While Joomla 5 is not immune to critical security flaws, the current threat landscape does not show a similar widespread, unauthenticated mass exploitation campaign at the scale seen in WordPress. Instead, Joomla's recent high-severity patches address authenticated RCE vectors and critical core flaws:

Joomla 5 Security Summary Details
Core RCE Vector Malicious File Uploads via Media Manager (CVE-2025-22213). This RCE requires an authenticated user with "edit" privileges (e.g., an Editor or higher role), a higher barrier than the unauthenticated WordPress flaws.
XSS-to-RCE Risk Cross-Site Scripting (XSS) flaws in the core filter component (CVE-2024-21726) could be leveraged to achieve RCE, but only by tricking an administrator into clicking a malicious link (requiring user interaction).
Extension Risk Joomla still faces authenticated RCE and SQL Injection risks in specific, unpatched third-party extensions, emphasizing that the largest CMS security threat often lies in add-on components, not the core.
Remediation Users must ensure they are on the latest versions, such as Joomla 5.3.4 or later, and apply all updates to third-party extensions immediately.

Conclusion: A Tale of Two CMS Risks

The difference in the observed attacks highlights the security challenges of each platform:

  • WordPress's Risk: Its massive market share and sprawling third-party plugin ecosystem make it a constant target for automated, non-discriminatory mass attacks that exploit unauthenticated flaws to gain initial access.

  • Joomla's Risk: While it has a generally stronger built-in user access control system, vulnerabilities still exist in its core and extensions, often requiring an authenticated user or an attack chain involving user interaction (like an administrator clicking a link) to achieve the most critical results, like RCE.

All site administrators are urged to prioritize security patches, especially for third-party add-ons, regardless of the CMS platform.

 


Website development resources recomended by StormWarning!

Should you still be wanting to have a secure corporate website built for you please use one of these recomended resources:
  • Plum Systems

    • We build beautiful professional websites that clearly represent the clients brand and mission. More importantly, the  websites and web portals we design offer full interactive business support solutions making them so much more than just a web brochure. The web presences we create actively solve system and process issues and increase business automation.
    • Contact Plum Systems

  • DEVTEQ

    • Discover top-notch, affordable website hosting services that combine reliability, speed, and exceptional support.
      Our hosting solutions cater to all your needs with robust features, seamless performance, and unbeatable prices.
      Experience unparalleled uptime, easy scalability, and 24/7 customer support with our cost-effective hosting plans. Get your website online effortlessly and affordably with our premium hosting services.
    • Contact DEVTEQ

  • WebExpert

    • We specialise in creating affordable, powerful websites exclusively using well known platforms renowned for their robust security, built-in advanced features like sophisticated user access controls and multilingual support, and exceptional scalability. We offer professional results without the premium price tag by leveraging open-source efficiency, allowing your budget to deliver more power and functionality than simple website builders. Choose WebExpert to get a fast, secure, and feature-rich online presence built by dedicated platform specialists, ensuring your business has a superior foundation for future growth.
    • Contact WebExpert

 

Related Articles

What is StormWarning! ?

 StormWarning! is a Cybersecurity consultancy. Our experienced team of cybersecurity experts provide cybersecurity assessments, cybersecurity training and cybersecurity solutions to organisations that have a high risk public profile. StormWarning! is your organisation's best defense against the ever growing cascade of innovative security threats raining down on all organisations with a public digital footprint.

What is Cybersecurity?

Cybersecurity is the practice of protecting critical systems and sensitive information from digital attacks. Also known as information technology (IT) security, cybersecurity measures are designed to combat threats against networked systems and applications, whether those threats originate from inside or outside of an organization. StormWarning! is constantly researching the latest cybersecurity threats and building innovative measures to prevent them.

 

NIST Audit & Targeted Cyber-Risk Training

StormWarning! offers comprehensive Cybersecurity Consulting, with a focus on its Automated Online Auditing Solutions, primarily the NIST CSF Readiness Audit. This audit is prioritized as its results directly inform the organization's needs for targeted cybersecurity training. By identifying specific gaps in risk management knowledge, they deliver precise education via Short Courses—like Cybersecurity Risk Management or Understanding Cybersecurity GRC—to ensure staff and leadership close deficiencies and maintain compliance.

Their full suite of services also includes robust Risk Management planning, development of essential Policies, impactful Cybersecurity Awareness Campaigns, and a security monitoring/incident response platform, StormFront. Additionally, we offer a resource library of Cybersecurity Books authored by our esteemed associate Dr. Zoran Mitrovic.