{"id":8097,"date":"2025-10-27T11:10:11","date_gmt":"2025-10-27T11:10:11","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=8097"},"modified":"2025-10-27T11:10:11","modified_gmt":"2025-10-27T11:10:11","slug":"12-months-previous-wordpress-plugin-flaws-exploited-to-hack-web-sites","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=8097","title":{"rendered":"12 months-Previous WordPress Plugin Flaws Exploited to Hack Web sites"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><strong>Three critical-severity vulnerabilities within the GutenKit and Hunk Companion WordPress plugins have been exploited in a brand new marketing campaign, Defiant warns.<\/strong><\/p>\n<p>Mass exploitation of the safety defects began on October 8, with roughly 9 million exploit makes an attempt blocked by the WordPress safety agency over a two-week interval, and follows beforehand recognized large-scale campaigns focusing on the identical bugs.<\/p>\n<p>GutenKit variations previous to 2.1.1 are affected by CVE-2024-9234, a lacking functionality test subject resulting in arbitrary file uploads. The flaw permits attackers to put in and activate arbitrary plugins or add information masquerading as plugins.<\/p>\n<p>Hunk Companion variations previous to 1.8.4 and 1.8.5 are weak to unauthorized plugin set up\/activation as a consequence of two lacking functionality test vulnerabilities within the \u2018themehunk-import\u2019 REST API endpoint.<\/p>\n<p>Tracked as CVE-2024-9707 and CVE-2024-11972, the issues enable unauthenticated attackers to put in plugins and obtain distant code execution by means of different weak plugins.<\/p>\n<p>As a part of <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.wordfence.com\/blog\/2025\/10\/mass-exploit-campaign-targeting-arbitrary-plugin-installation-vulnerabilities\/\">the current assaults<\/a> focusing on the three safety defects, the risk actor has distributed a malicious ZIP file posing as a plugin, which is hosted on GitHub.<\/p>\n<p>The file comprises a number of scripts that act as backdoors, and makes an attempt to determine persistence. A script within the archive permits attackers to mechanically log in as directors.<\/p>\n<p>The ZIP additionally contains scripts that change file permissions, permitting the attackers to obtain and examine information, and to archive whole folders into ZIP information. Different file add\/supervisor scripts are additionally included within the code.<\/p>\n<div class=\"zox-post-ad-wrap\"><span class=\"zox-ad-label\">Commercial. Scroll to proceed studying.<\/span><\/div>\n<p>One other file within the archive is a instrument able to mass defacement, community sniffing, and file administration. It additionally has distant code execution performance, permitting the attackers to deploy extra payloads.<\/p>\n<p>GutenKit and Hunk Companion have over 40,000 and eight,000 lively installations, respectively. Though the exploited vulnerabilities have been patched over a yr in the past, they proceed to signify engaging targets for risk actors, because the contemporary marketing campaign reveals.<\/p>\n<p>Website directors are suggested to replace their plugins to the newest, patched variations, and to overview the indications of compromise (IOCs) shared by Defiant to establish potential compromise.<\/p>\n<p><strong>Associated:<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/flaw-allowing-website-takeover-found-in-wordpress-plugin-with-400k-installations\/\">Flaw Permitting Web site Takeover Present in WordPress Plugin With 400k Installations<\/a><\/p>\n<p><strong>Associated:<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/hackers-inject-malware-into-gravity-forms-wordpress-plugin\/\">Hackers Inject Malware Into Gravity Kinds WordPress Plugin<\/a><\/p>\n<p><strong>Associated:<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/forminator-wordpress-plugin-vulnerability-exposes-400000-websites-to-takeover\/\">Forminator WordPress Plugin Vulnerability Exposes 400,000 Web sites to Takeover<\/a><\/p>\n<p><strong>Associated:<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/motors-theme-vulnerability-exploited-to-hack-wordpress-websites\/\">Motors Theme Vulnerability Exploited to Hack WordPress Web sites<\/a>\n\t\t\t<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Three critical-severity vulnerabilities within the GutenKit and Hunk Companion WordPress plugins have been exploited in a brand new marketing campaign, Defiant warns. Mass exploitation of the safety defects began on October 8, with roughly 9 million exploit makes an attempt blocked by the WordPress safety agency over a two-week interval, and follows beforehand recognized large-scale [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":8099,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1994,1812,940,4470,105,3852,6122],"class_list":["post-8097","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-exploited","tag-flaws","tag-hack","tag-plugin","tag-websites","tag-wordpress","tag-yearold"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8097","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8097"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8097\/revisions"}],"predecessor-version":[{"id":8098,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8097\/revisions\/8098"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/8099"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8097"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8097"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8097"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-15 10:36:48 UTC -->