The attackers massively hack websites around the world and install hidden means on servers to remotely manage them. The campaign has already affected many small and medium-sized companies in Australia, but the attacks are not limited to one country.
The Australian Cyber Security Center said the attackers automatically scan sites and search for vulnerable content management and expansion systems. The errors found allow you to upload files without authorization, execute commands on the server, send requests on its behalf or process specially prepared data.
After the site is hacked, the attackers install web shells that give constant remote access to the server. Through them, criminals can change or disconnect sites, intercept passwords entered by visitors, steal stored data, download malware, and use the server as an entry point in the company’s internal network.
The campaign employs vulnerabilities in the following programmes and extensions:
Simple File List for WordPress – CVE-2020-36847 (9.8 Critical). The CVE-2025-34085 warnings have been rejected as a duplicate of this vulnerability;
WavePlayer for WordPress – CVE-2025-12057 (9.8 Critical);
BerqWP for WordPress – CVE-2025-7443 (8.1 High);
WPBookit for WordPress – CVE-2025-7852 (9.8 Critical);
Ninja Forms File Uploads for WordPress CVE-2026-0740 (9.8 Critical);
ThemeREX Addons for WordPress CVE-2026-1969 (9.8 Critical);
Breeze Cache for WordPress – CVE-2026-3844 (9.8 Critical);
Pay-uz for WordPress – CVE-2026-31843 (10.0 Critical);
Advanced Custom Fields: Extended for WordPress CVE-2025-13486 (9.8 Critical);
Sneeit Framework for WordPress – CVE-2025-6389 (9.8 Critical);
WPvivid Backup & Migration for WordPress – CVE-2026-1357 (9.8 Critical);
Gravity Forms for WordPress – CVE-2025-12352 (9.8 Critical);
GuttenKit and Hunk Companion for WordPress CVE-2024-9234 (9.8 Critical). The Australian Cyber Security Center believes the linking of attacks with this vulnerability is likely;
Craft CMS – CVE-2025-32432 (9.8 Critical);
MaxSite CMS – CVE-2026-3395 (7.3 High);
MetInfo CMS – CVE-2026-29014 (9.8 Critical);
Joomla Content Editor – CVE-2026-48907 (10.0 Critical).
Australian experts advise to check the catalogs of sites and extensions to unknown or recently modified files, and access logs to suspicious requests GET and POST. A server with a found web sheath should be considered completely compromised, isolated from the network and check if new accounts and malware appeared, have not attempted to output data and whether they moved between the systems.
Administrators are also advised to study earlier entries in the logs and find queries through which attackers could initially hack the site and load the web sheath. Network logs and online screen recordings will help detect the connections of the infected server with external addresses.
Vulnerable components need to be updated, and extensions without correction temporarily disconnect. After malicious files are removed or isolated, the server cannot be returned to the network until it is fully checked. If the site is hacked, it is recommended to be restored from a recent clean backup.
To further protect themselves, organizations are offered to prohibit the site directory where nothing should change, limit access to files and paths, monitor what child processes the web server runs, and separate public sites from the corporate network. If the fixes are set automatically, this can also shorten the time during which the site remains vulnerable.
If you can not completely prohibit the creation of files, administrators are advised to monitor any changes that go beyond the approved works. This approach helps to quickly detect the web sheath and reduce its life on an infected server.
The Australian Cyber Security Center said the attackers automatically scan sites and search for vulnerable content management and expansion systems. The errors found allow you to upload files without authorization, execute commands on the server, send requests on its behalf or process specially prepared data.
After the site is hacked, the attackers install web shells that give constant remote access to the server. Through them, criminals can change or disconnect sites, intercept passwords entered by visitors, steal stored data, download malware, and use the server as an entry point in the company’s internal network.
The campaign employs vulnerabilities in the following programmes and extensions:
Simple File List for WordPress – CVE-2020-36847 (9.8 Critical). The CVE-2025-34085 warnings have been rejected as a duplicate of this vulnerability;
WavePlayer for WordPress – CVE-2025-12057 (9.8 Critical);
BerqWP for WordPress – CVE-2025-7443 (8.1 High);
WPBookit for WordPress – CVE-2025-7852 (9.8 Critical);
Ninja Forms File Uploads for WordPress CVE-2026-0740 (9.8 Critical);
ThemeREX Addons for WordPress CVE-2026-1969 (9.8 Critical);
Breeze Cache for WordPress – CVE-2026-3844 (9.8 Critical);
Pay-uz for WordPress – CVE-2026-31843 (10.0 Critical);
Advanced Custom Fields: Extended for WordPress CVE-2025-13486 (9.8 Critical);
Sneeit Framework for WordPress – CVE-2025-6389 (9.8 Critical);
WPvivid Backup & Migration for WordPress – CVE-2026-1357 (9.8 Critical);
Gravity Forms for WordPress – CVE-2025-12352 (9.8 Critical);
GuttenKit and Hunk Companion for WordPress CVE-2024-9234 (9.8 Critical). The Australian Cyber Security Center believes the linking of attacks with this vulnerability is likely;
Craft CMS – CVE-2025-32432 (9.8 Critical);
MaxSite CMS – CVE-2026-3395 (7.3 High);
MetInfo CMS – CVE-2026-29014 (9.8 Critical);
Joomla Content Editor – CVE-2026-48907 (10.0 Critical).
Australian experts advise to check the catalogs of sites and extensions to unknown or recently modified files, and access logs to suspicious requests GET and POST. A server with a found web sheath should be considered completely compromised, isolated from the network and check if new accounts and malware appeared, have not attempted to output data and whether they moved between the systems.
Administrators are also advised to study earlier entries in the logs and find queries through which attackers could initially hack the site and load the web sheath. Network logs and online screen recordings will help detect the connections of the infected server with external addresses.
Vulnerable components need to be updated, and extensions without correction temporarily disconnect. After malicious files are removed or isolated, the server cannot be returned to the network until it is fully checked. If the site is hacked, it is recommended to be restored from a recent clean backup.
To further protect themselves, organizations are offered to prohibit the site directory where nothing should change, limit access to files and paths, monitor what child processes the web server runs, and separate public sites from the corporate network. If the fixes are set automatically, this can also shorten the time during which the site remains vulnerable.
If you can not completely prohibit the creation of files, administrators are advised to monitor any changes that go beyond the approved works. This approach helps to quickly detect the web sheath and reduce its life on an infected server.