HomeSecurityHackers target sites through outdated WordPress plugins

Hackers target sites through outdated WordPress plugins

A new campaign is targeting WordPress sites running old versions of the GutenKit and Hunk Companion plugins, which are vulnerable to three critical RCE (remote code execution) security flaws. Security firm Wordfence says it blocked 8.7 million attack attempts in just two days, October 8 and 9, a testament to the intensity and automated nature of the campaign.

WordPress plugins GutenKit and Hunk Companion

WordPress – GutenKit & Hunk Companion plugins: Vulnerabilities

The vulnerabilities — CVE-2024-9234, CVE-2024-9707, and CVE-2024-11972 — were rated critical (CVSS 9.8). CVE-2024-9234 concerns an unauthorized REST endpoint in GutenKit (affecting versions 2.1.0 and earlier), which allows the installation of arbitrary plugins without authentication. CVE-2024-9707 and CVE-2024-11972 are found in the themehunk-import REST endpoint in Hunk Companion (affecting versions up to 1.8.4 and 1.8.5, respectively) and also bypass authorization checks.

See also: New phishing campaign targets LastPass users

Attack mechanism and examples of malicious payloads

According to Wordfence, the threat actors are hosting a malicious plugin in a .ZIP file called 'up'. This contains scripts for uploading, downloading, deleting files , and changing permissions. One of the scripts allows the attacker to automatically log in as an administrator.

Attackers use these tools to maintain persistence, steal or dump files, execute commands, or intercept private data handled by the website.

When full admin access is not available, attackers often install the vulnerable 'wp-query-console' plugin to gain RCE capability.

Hackers target sites through outdated WordPress plugins

Signs of tampering and technical indications

Wordfence highlights requests that administrators should review in the logs: /wp-json/gutenkit/v1/install-active-plugin and /wp-json/hc/v1/themehunk-import. Also, directories like /up, /background-image-cropper, /ultra-seo-processor-wp, /oke, and /wp-query-console may contain fake entries or backdoors. Administrators should check regularly.

See also: Firefox: New extensions must declare data collection practices

Researchers have recorded IP addresses associated with the exploit activity.

Updates and recovery

Patches for the vulnerabilities in the WordPress plugins GutenKit and Hunk Companion have been released for a long time: GutenKit 2.1.1 (October 2024) and Hunk Companion 1.9.0 (December 2024). However, many websites are still running vulnerable versions—a common cause of widespread attacks that exploit the update delay.

Immediately update plugins to the latest version, check logs for the above endpoints, remove suspicious files and directories, change passwords , and review administrator accounts. Perform a full security scan and, if a breach is suspected, reinstall from clean sources and restore from a reliable backup.

Preventive measures and security policies

Beyond technical fixes, administrators should adopt patch management, privilege restrictions, and systematic auditing. This includes automatic updates when possible, enabling WAF with rules to block requests to vulnerable endpoints, and limiting allowed plugins to only trusted sources.

Implications for business and SEO

A WordPress breach can immediately impact a website's traffic and reputation. Infected pages are often downgraded by search engines, while online stores risk leaking sensitive customer data, with legal and financial consequences.

See also: Microsoft prevents NTLM Hashes leaks

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Hackers target sites through outdated WordPress plugins

Tips for immediate shielding

In addition to necessary updates, enable two-factor authentication on administrator accounts, restrict file permissions, and implement rate limiting rules. Use file integrity checks and WAFs with rules that block requests to known vulnerable endpoints.

The scope of the campaign highlights that WordPress security is a matter of maintenance and process; plugins are not innocent, and an old plugin can become a front door for a widespread breach. Administrators who invest in prevention and rapid updates drastically reduce risk and remediation costs. Invest in staff training and 24/7 continuous monitoring.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS