• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

12 months-Previous WordPress Plugin Flaws Exploited to Hack Web sites

Admin by Admin
October 27, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Three critical-severity vulnerabilities within the GutenKit and Hunk Companion WordPress plugins have been exploited in a brand new marketing campaign, Defiant warns.

Mass exploitation of the safety defects began on October 8, with roughly 9 million exploit makes an attempt blocked by the WordPress safety agency over a two-week interval, and follows beforehand recognized large-scale campaigns focusing on the identical bugs.

GutenKit variations previous to 2.1.1 are affected by CVE-2024-9234, a lacking functionality test subject resulting in arbitrary file uploads. The flaw permits attackers to put in and activate arbitrary plugins or add information masquerading as plugins.

Hunk Companion variations previous to 1.8.4 and 1.8.5 are weak to unauthorized plugin set up/activation as a consequence of two lacking functionality test vulnerabilities within the ‘themehunk-import’ REST API endpoint.

Tracked as CVE-2024-9707 and CVE-2024-11972, the issues enable unauthenticated attackers to put in plugins and obtain distant code execution by means of different weak plugins.

As a part of the current assaults focusing on the three safety defects, the risk actor has distributed a malicious ZIP file posing as a plugin, which is hosted on GitHub.

The file comprises a number of scripts that act as backdoors, and makes an attempt to determine persistence. A script within the archive permits attackers to mechanically log in as directors.

The ZIP additionally contains scripts that change file permissions, permitting the attackers to obtain and examine information, and to archive whole folders into ZIP information. Different file add/supervisor scripts are additionally included within the code.

Commercial. Scroll to proceed studying.

One other file within the archive is a instrument able to mass defacement, community sniffing, and file administration. It additionally has distant code execution performance, permitting the attackers to deploy extra payloads.

GutenKit and Hunk Companion have over 40,000 and eight,000 lively installations, respectively. Though the exploited vulnerabilities have been patched over a yr in the past, they proceed to signify engaging targets for risk actors, because the contemporary marketing campaign reveals.

Website directors are suggested to replace their plugins to the newest, patched variations, and to overview the indications of compromise (IOCs) shared by Defiant to establish potential compromise.

Associated: Flaw Permitting Web site Takeover Present in WordPress Plugin With 400k Installations

Associated: Hackers Inject Malware Into Gravity Kinds WordPress Plugin

Associated: Forminator WordPress Plugin Vulnerability Exposes 400,000 Web sites to Takeover

Associated: Motors Theme Vulnerability Exploited to Hack WordPress Web sites

Tags: ExploitedFlawsHackPluginwebsitesWordPressYearOld
Admin

Admin

Next Post
Professional Distant Pc Restore Providers for Queens Residents by Technico

Professional Distant Pc Restore Providers for Queens Residents by Technico

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025
Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

By no means one to lag behind HSR and ZZZ, Genshin Influence will introduce its personal new pink-haired animal-themed woman in Model Luna 6

By no means one to lag behind HSR and ZZZ, Genshin Influence will introduce its personal new pink-haired animal-themed woman in Model Luna 6

March 28, 2026
Iran-Linked Handala Hackers Breach FBI Chief Kash Patel’s Gmail

Iran-Linked Handala Hackers Breach FBI Chief Kash Patel’s Gmail

March 28, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved