CyberzSOC

Publication detail
← Back to advisories & guidance

CRITICAL ALERT: Large-scale exploitation campaign targeting website content management systems (CMS) ↗ source

July 9, 2026 ASD/ACSC Alert

Summary

As part of this campaign, malicious cyber actors are actively scanning websites for opportunities to deploy webshells, leveraging various vulnerabilities affecting CMS software and plugins. These vulnerabilities primarily allow unauthenticated file upload, remote code execution, server side request forgery or deserialisation. Once deployed, webshells can allow malicious cyber actors to remotely access and control targeted web servers. Malicious cyber actors may leverage compromised web servers for several purposes, including: Website defacement or disruption Capturing credentials entered by website users or other data stored on web servers Uploading additional malware to target and scam legitimate website users Using web server access as a pathway for broader network compromise The software, plugins and CVEs being exploited include: GutenKit/Hunk Companion (WordPress) This highly scaled global exploitation campaign demonstrates the rapidly evolving cyber risk facing organisations.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-32432 10.0 Critical Craft CMS Craft CMS Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
CVE-2026-31843 10.0 Critical goodoneuz pay-uz The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthent…
CVE-2026-48907 10.0 Critical Widget Factory Joomla Content Editor Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the…
CVE-2020-36847 9.8 Critical eemitch Simple File List The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.2.2 via the rename function whic…
CVE-2024-9234 9.8 Critical ataurr GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads d…
CVE-2025-12057 9.8 Critical Unknown WavePlayer The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally…
CVE-2025-12352 9.8 Critical Gravity Forms Gravity Forms The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the copy_post_image() function …
CVE-2025-13486 9.8 Critical hwk-fr Advanced Custom Fields: Extended The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_…
CVE-2025-6389 9.8 Critical Sneeit Sneeit Framework The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pa…
CVE-2025-7852 9.8 Critical iqonicdesign WPBookit The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function h…
CVE-2026-0740 9.8 Critical SaturdayDrive Ninja Forms - File Uploads The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Co…
CVE-2026-1357 9.8 Critical wpvividplugins Migration, Backup, Staging – WPvivid Backup & Migration The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions u…
CVE-2026-3844 9.8 Critical cloudways Breeze Cache The Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fetch_gravatar_from_remote'…
CVE-2026-29014 9.3 Critical MetInfo CMS MetInfo CMS MetInfo CMS versions 7.9, 8.0, and 8.1 contain an unauthenticated PHP code injection vulnerability that allows remote attackers to execute arbitrary …
CVE-2025-7443 8.1 High berqwp BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript The BerqWP – Automated All-In-One Page Speed Optimization for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulner…
CVE-2026-3395 6.9 Medium MaxSite CMS A flaw has been found in MaxSite CMS up to 109.1. This impacts the function eval of the file application/maxsite/admin/plugins/editor_markitup/previe…
CVE-2026-1969 5.3 Medium Unknown trx_addons The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upl…
CVE-2025-34085 — —

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.