Executive Summary
In June 2024, a mass exploitation campaign targeted thousands of WordPress websites worldwide by abusing known critical vulnerabilities in the GutenKit and Hunk Companion plugins. Attackers leveraged outdated versions lacking essential security patches to achieve remote code execution (RCE), enabling full control over affected sites. The campaign's automated exploits installed malicious payloads, manipulated website content, and frequently enabled further lateral movement or data theft. Organizations relying on vulnerable plugins faced significant reputational and operational disruption, with site defacements, malware delivery, and potential customer data exposure as key impacts.
The incident highlights the persistent security challenge posed by unpatched plugins in popular web platforms. Amid a surge in mass web exploitation and supply chain attacks against CMS ecosystems, adversaries are rapidly weaponizing public proof-of-concept exploits, putting organizations at immediate risk from even dated vulnerabilities.
Why This Matters Now
This incident is urgent as it demonstrates attackers' ability to swiftly exploit widely used third-party plugins across innumerable organizations, bypassing traditional perimeters. The scale and speed of this campaign underscore the ongoing risk posed by delayed patching and lack of visibility into software supply chain exposure, making immediate remediation and improved controls critical.
Attack Path Analysis
Attackers exploited outdated and vulnerable WordPress plugins to gain unauthorized initial access to website environments. Post-compromise, they potentially escalated privileges by leveraging the compromised web application context to access broader system or application-level permissions. Once inside, adversaries could attempt lateral movement to adjacent workloads or services within the same cloud or on-premise environment. The attackers established command and control channels, often utilizing outbound connections to receive instructions or exfiltrate data. Sensitive information, website data, or credentials may have been exfiltrated through unmonitored egress paths. Ultimately, attackers could impact systems through website defacement, deployment of malicious payloads, or facilitating ransomware, disrupting business operations and damaging data integrity.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited critical remote code execution vulnerabilities in outdated WordPress plugins (GutenKit, Hunk Companion) to gain unauthorized access to web servers.
Related CVEs
CVE-2024-9707
CVSS 9.8The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.
Affected Products:
ThemeHunk Hunk Companion – <= 1.8.4
Exploit Status:
exploited in the wildCVE-2024-9234
CVSS 9.8The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API endpoint) in all versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins, or utilize the functionality to upload arbitrary files spoofed like plugins.
Affected Products:
Ataur R GutenKit – <= 2.1.0
Exploit Status:
exploited in the wildCVE-2024-11972
CVSS 9.8The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API endpoints, allowing unauthenticated requests to install and activate arbitrary plugins from the WordPress.org repo, including vulnerable plugins that have been closed.
Affected Products:
ThemeHunk Hunk Companion – < 1.9.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter
Valid Accounts: Web Services
Ingress Tool Transfer
Server Software Component: Web Shell
Hijack Execution Flow: DLL Side-Loading
Exploitation for Defense Evasion
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Security of System Components and Software
Control ID: 6.2.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy and Access Controls
Control ID: 500.03, 500.07
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA Zero Trust Maturity Model 2.0 – Continuous Asset Vulnerability Management
Control ID: Asset Management: Device Security
NIS2 Directive – Technical and Organizational Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
WordPress plugin vulnerabilities expose critical web applications to RCE attacks, requiring immediate zero trust segmentation and egress security controls.
Information Technology/IT
Mass WordPress exploitation campaigns target IT infrastructure through outdated plugins, demanding enhanced threat detection and multicloud visibility frameworks.
Marketing/Advertising/Sales
WordPress-dependent marketing platforms face RCE threats from GutenKit vulnerabilities, necessitating cloud firewall protection and encrypted traffic monitoring.
Media Production
Content management systems using vulnerable WordPress plugins risk remote code execution, requiring inline IPS protection and anomaly response capabilities.
Sources
- Hackers launch mass attacks exploiting outdated WordPress pluginshttps://www.bleepingcomputer.com/news/security/hackers-launch-mass-attacks-exploiting-outdated-wordpress-plugins/Verified
- CVE-2024-9707 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2024-9707Verified
- CVE-2024-9234 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2024-9234Verified
- CVE-2024-11972 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2024-11972Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust segmentation, east-west traffic controls, inline IPS, and egress enforcement would have restricted unauthorized movement, detected exploitation, and contained the scope of the attack, preventing mass exploitation and data leakage.
Control: Inline IPS (Suricata)
Mitigation: Malicious exploit signatures are detected and blocked in real time at network ingress.
Control: Zero Trust Segmentation
Mitigation: Attackers are unable to leverage compromise to reach privileged internal systems.
Control: East-West Traffic Security
Mitigation: Unusual internal traffic patterns are detected and blocked between workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Unauthorized external command channels are blocked and alerted.
Control: Multicloud Visibility & Control
Mitigation: Anomalous data egress is detected and contained before major loss.
Automated, distributed policy enforcement limits blast radius and accelerates incident recovery.
Impact at a Glance
Affected Business Functions
- Website Operations
- Customer Engagement
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of customer data and website content due to unauthorized plugin installations and remote code execution.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce network and application-level segmentation to contain potential compromises to the exposed web servers.
- • Deploy inline intrusion prevention systems at cloud ingress to detect and block exploitation of known vulnerabilities in real time.
- • Apply strict egress filtering to prevent unauthorized outbound connections and data exfiltration from web and application workloads.
- • Continuously monitor east-west traffic between workloads for anomalous movement and restrict unnecessary internal communication.
- • Implement centralized, multi-cloud visibility and rapid incident response workflows to quickly detect and remediate emerging threats.



