Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Year-Old WordPress Plugin Flaws Exploited to Hack Websites

Roughly 9 million exploit attempts were observed this month as mass exploitation of the critical vulnerabilities recommenced.

WordPress vulnerability exploited

Three critical-severity vulnerabilities in the GutenKit and Hunk Companion WordPress plugins have been exploited in a new campaign, Defiant warns.

Mass exploitation of the security defects started on October 8, with roughly 9 million exploit attempts blocked by the WordPress security firm over a two-week period, and follows previously identified large-scale campaigns targeting the same bugs.

GutenKit versions prior to 2.1.1 are affected by CVE-2024-9234, a missing capability check issue leading to arbitrary file uploads. The flaw allows attackers to install and activate arbitrary plugins or upload files masquerading as plugins.

Hunk Companion versions prior to 1.8.4 and 1.8.5 are vulnerable to unauthorized plugin installation/activation due to two missing capability check vulnerabilities in the ‘themehunk-import’ REST API endpoint.

Tracked as CVE-2024-9707 and CVE-2024-11972, the flaws allow unauthenticated attackers to install plugins and achieve remote code execution through other vulnerable plugins.

As part of the recent attacks targeting the three security defects, the threat actor has distributed a malicious ZIP file posing as a plugin, which is hosted on GitHub.

Advertisement. Scroll to continue reading.

The file contains several scripts that act as backdoors, and attempts to establish persistence. A script in the archive allows attackers to automatically log in as administrators.

The ZIP also includes scripts that change file permissions, allowing the attackers to download and view files, and to archive entire folders into ZIP files. Other file upload/manager scripts are also included in the code.

Another file in the archive is a tool capable of mass defacement, network sniffing, and file management. It also has remote code execution functionality, allowing the attackers to deploy additional payloads.

GutenKit and Hunk Companion have over 40,000 and 8,000 active installations, respectively. Although the exploited vulnerabilities were patched over a year ago, they continue to represent attractive targets for threat actors, as the fresh campaign shows.

Site administrators are advised to update their plugins to the most recent, patched versions, and to review the indicators of compromise (IOCs) shared by Defiant to identify potential compromise.

Related: Flaw Allowing Website Takeover Found in WordPress Plugin With 400k Installations

Related: Hackers Inject Malware Into Gravity Forms WordPress Plugin

Related: Forminator WordPress Plugin Vulnerability Exposes 400,000 Websites to Takeover

Related: Motors Theme Vulnerability Exploited to Hack WordPress Websites

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

PNC Financial Services Group has appointed Christian Winward as CISO.

Brian Gumbel has joined Armadin as Chief Revenue Officer.

EigenQ has appointed Mark Pecen as Vice Chairman and Alexander Truskovsky as CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.