The Australian Cyber Security Centre warns that attackers are breaking into websites worldwide
through 17 known flaws in popular website software, mostly WordPress plugins, and planting hidden
backdoors called webshells. Many small and medium Australian businesses are already compromised.
Website owners should patch their software now and check their servers for signs of intrusion.
1.Campaign Timeline
ASD’s ACSC published a Critical alert in July 2026 tracking a large-scale exploitation campaign against content management systems globally, including in Australia, with many small to medium sized Australian businesses impacted. Actors scan websites at scale for vulnerable CMS software and plugins, then deploy webshells for persistent remote access. The exploited flaws primarily allow unauthenticated file upload, remote code execution, server side request forgery, or deserialisation. All targeted CVEs are public and known vulnerabilities with patches available, except the GutenKit/Hunk Companion case, which ACSC assesses as likely CVE-2024-9234.
2. Exploited Software and CVEs
Simple File List (CVE-2025-34085/CVE-2020-36847), WavePlayer (CVE-2025-12057), BerqWP (CVE-2025-7443), WPBookit (CVE-2025-7852), Ninja Forms (CVE-2026-0740), ThemeREX Addons (CVE-2026-1969), Breeze Cache (CVE-2026-3844), pay-uz (CVE-2026-31843), ACF Extended (CVE-2025-13486), Sneeit Framework (CVE 2025-6389), WPvivid Backup (CVE-2026-1357), Gravity Forms (CVE-2025-12352), GutenKit/Hunk Companion (likely CVE-2024-9234), Craft CMS (CVE-2025-32432), MaxSite CMS (CVE-2026-3395), MetInfo CMS (CVE 2026-29014), and Joomla JCE (CVE-2026-48907). All except the last four are WordPress plugins. Targeting is opportunistic and global, not sector-specific.
3. Attack Chain
Scanning
Actors actively scan internet-facing websites for CMS software and plugin versions carrying any of the 17
exploitable CVEs.
Exploitation
Unauthenticated file upload, remote code execution, server side request forgery, or deserialisation flaws give the actor a foothold on the web server.
Webshell deployment
A webshell is written into the web or plugin directory, giving the actor persistent remote access and control of the server.
Post-compromise use
Compromised servers are used for defacement or disruption, capturing credentials entered by site users,
uploading malware to scam visitors, and as a pathway into the broader network.
4. Indicators of Compromise (IOCs)
5. Recommendations
- Inspect web and plugin directories for abnormal or recently created files, and check web access logs for GET or POST requests to unexpected script paths.
- Treat any server hosting a webshell as compromised: isolate it, audit authentication and network logs for lateral movement, then restore the site from a known-good backup.
- Patch CMS core, themes, and plugins to the latest versions before reconnecting remediated servers.
- Remove or disable unused plugins and enable automatic updates where rollback is easy.
- Set web directories read-only where possible, monitor for file creation outside approved changes, and block or alert on unexpected child processes spawned by the web server.
- Block unnecessary network communication between internet-facing websites and other corporate systems to limit broader network compromise.
6. Sources
- https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/large-scale-exploi
tation-campaign-targeting-website-content-management-systems-cms - https://www.bleepingcomputer.com/news/security/australia-warns-of-global-campaign-targeting-vulnerable-cms-platforms/
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.