Cybersecurity

Hackers are attacking millions of WordPress sites through critical vulnerabilities in popular plugins

clock icon October 27, 2025

A major exploitation campaign has hit WordPress-based websites, with attackers targeting recipients who install the Gutenberg and Nunk Companion plugins, which contain critical vulnerabilities that could allow arbitrary code execution. Wordfence, a WordPress security company, recorded 8.7 million attack attempts in just two days – October 8th and 9th.

The campaign exploits three vulnerabilities, registered under the numbers CVE-2024-9234, CVE-2024-9707 and CVE-2024-11972. All of them have a maximum threat level of CVSS 9.8. The first of them (CVE-2024-9234) was discovered in the Gutenberg plugin with over 40,000 active installations. The REST endpoint vulnerability allows the remote installation of any application without permission and authentication.

Two other vulnerabilities (CVE-2024-9707 and CVE-2024-11972) are present in the themehunk-import component of the Hunk Comparison plugin, which is installed on around 8,000 sites. They are also related to the lack of authorization checking when accessing the REST endpoint, which allows an attacker to install an arbitrary plugin, including one with malicious code. Once the additional extension is installed, an attacker can execute arbitrary commands on the server and achieve remote code execution (RCE).

Vulnerability CVE-2024-9234 affects versions 2.1.0 and earlier of GutenKit. Vulnerabilities CVE-2024-9707 and CVE-2024-11972 occur in versions 1.8.4 and 1.8.5 of Nunk Comparison, respectively, as well as in all previous versions. The fixes appeared almost a year ago in GutenKit 2.1.1 (October 2024) and Nunc Compiler 1.9.0 (December 2024), but many sites will still use old, vulnerable compilations.

According to Wordfense, attackers are distributing a malicious ur.zir archive on GitHub containing a hidden file. Inside the archive are encrypted scripts that allow files to be accessed, deleted, and modified, as well as to manage permissions. One of the files, password-protected and disguised as an All in One SEO component, is used to automatically log in an attacker with an administrator account.

Once the plugin is installed, attackers gain stable access to the server: they can download or steal data, execute system commands, and monitor personal information processed by the site. If a full backdoor cannot be installed, another plugin is used – wp-query-console, which has its own vulnerability that allows arbitrary code execution without authorization.

Wordfense publishes a list of IP addresses from which the main flow of malicious requests originates, which can be used to configure server-level filtering. Among the known compromises, experts recommend checking the request logs:

/wр-јѕоn/gutеnkіt/v1/іnѕtаll-асtіvе-рlugіn

/wр-јѕоn/hс/v1/thеmеhunk-іmроrt

You should also check the directories /up, /background-image-chopper, /ultra-seo-processor-wp, /oke and /wp-query-console – the presence of unknown files in them may indicate a hacker attack.

Don't forget that the only reliable way to protect yourself is to regularly update all plugins and use versions in which vulnerabilities have been removed by the developers.

Source: https://www.kaldata.com/

Join

Start your career transformation today

Are you ready to develop your IT skills and achieve your career goals? Enroll in our courses now and start learning from leading industry experts.

Start now
    0
    Selected courses
    Your cart is empty.