Hackers launch mass attacks exploiting outdated WordPress plugins
ID: 622dfdcf-ee1f-5261-8ef2-eabbf12da29d
STIX ID: report--622dfdcf-ee1f-5261-8ef2-eabbf12da29d
Feed Name: Bleeping Computer
**Mass exploitation of outdated WordPress plugins:** A large-scale campaign is actively exploiting critical RCE-enabling flaws in the GutenKit and Hunk Companion plugins (CVSS 9.8) to install malicious plugins and backdoors; Wordfence observed 8.7 million blocked attempts in two days and researchers identified malicious .zip payloads and IOCs (REST endpoints and directories) to detect compromise—administrators are advised to patch/upgrade affected plugins and inspect logs and filesystem paths.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
