• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

12 months-Previous WordPress Plugin Flaws Exploited to Hack Web sites

Admin by Admin
October 27, 2025
Home Cybersecurity
Share on FacebookShare on Twitter


Three critical-severity vulnerabilities within the GutenKit and Hunk Companion WordPress plugins have been exploited in a brand new marketing campaign, Defiant warns.

Mass exploitation of the safety defects began on October 8, with roughly 9 million exploit makes an attempt blocked by the WordPress safety agency over a two-week interval, and follows beforehand recognized large-scale campaigns focusing on the identical bugs.

GutenKit variations previous to 2.1.1 are affected by CVE-2024-9234, a lacking functionality test subject resulting in arbitrary file uploads. The flaw permits attackers to put in and activate arbitrary plugins or add information masquerading as plugins.

Hunk Companion variations previous to 1.8.4 and 1.8.5 are weak to unauthorized plugin set up/activation as a consequence of two lacking functionality test vulnerabilities within the ‘themehunk-import’ REST API endpoint.

Tracked as CVE-2024-9707 and CVE-2024-11972, the issues enable unauthenticated attackers to put in plugins and obtain distant code execution by means of different weak plugins.

As a part of the current assaults focusing on the three safety defects, the risk actor has distributed a malicious ZIP file posing as a plugin, which is hosted on GitHub.

The file comprises a number of scripts that act as backdoors, and makes an attempt to determine persistence. A script within the archive permits attackers to mechanically log in as directors.

The ZIP additionally contains scripts that change file permissions, permitting the attackers to obtain and examine information, and to archive whole folders into ZIP information. Different file add/supervisor scripts are additionally included within the code.

Commercial. Scroll to proceed studying.

One other file within the archive is a instrument able to mass defacement, community sniffing, and file administration. It additionally has distant code execution performance, permitting the attackers to deploy extra payloads.

GutenKit and Hunk Companion have over 40,000 and eight,000 lively installations, respectively. Though the exploited vulnerabilities have been patched over a yr in the past, they proceed to signify engaging targets for risk actors, because the contemporary marketing campaign reveals.

Website directors are suggested to replace their plugins to the newest, patched variations, and to overview the indications of compromise (IOCs) shared by Defiant to establish potential compromise.

Associated: Flaw Permitting Web site Takeover Present in WordPress Plugin With 400k Installations

Associated: Hackers Inject Malware Into Gravity Kinds WordPress Plugin

Associated: Forminator WordPress Plugin Vulnerability Exposes 400,000 Web sites to Takeover

Associated: Motors Theme Vulnerability Exploited to Hack WordPress Web sites

Tags: ExploitedFlawsHackPluginwebsitesWordPressYearOld
Admin

Admin

Next Post
Professional Distant Pc Restore Providers for Queens Residents by Technico

Professional Distant Pc Restore Providers for Queens Residents by Technico

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

The right way to use Netdiscover to map and troubleshoot networks

The right way to use Netdiscover to map and troubleshoot networks

August 26, 2025
Learn how to Develop an App Like Uber in 2026

Learn how to Develop an App Like Uber in 2026

May 8, 2026
Prime AI Legacy System Modernization Firms in 2026

Prime AI Legacy System Modernization Firms in 2026

July 10, 2026
LLMs Are Studying to Assume in Steps | by Considering Loop | Aug, 2025

LLMs Are Studying to Assume in Steps | by Considering Loop | Aug, 2025

August 12, 2025
Discover a Software program Improvement Firm in Europe

Discover a Software program Improvement Firm in Europe

August 22, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

What the Hugging Face hack tells us about human accountability

What the Hugging Face hack tells us about human accountability

August 17, 2026
After 10 Years, Tom Cruise’s Forgotten 118-Minute Thriller-Thriller Is Again on Free Streaming

After 10 Years, Tom Cruise’s Forgotten 118-Minute Thriller-Thriller Is Again on Free Streaming

August 17, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved