Australia warns of global campaign targeting vulnerable CMS platforms

A Global Campaign of Cyber Attacks Targeting Vulnerable CMS Platforms Has Been Unleashed, Warns Australia’s Cyber Security Centre

Australian businesses are being warned about a massive global campaign targeting vulnerable content management systems (CMS) and plugins. The Australian Cyber Security Centre (ACSC) has issued an alert stating that many small to medium-sized enterprises in the country have already fallen victim to this malicious activity.

At the heart of these attacks are webshells, which provide persistent access to compromised websites and allow threat actors to wreak havoc on their victims’ online presence. Webshells can be used to disrupt services, steal sensitive information, plant additional malware, and move deeper into a network with impunity. The ACSC warns that this campaign is not limited to Australia, but rather is a global effort targeting vulnerable CMS platforms worldwide.

The Australian agency has identified multiple vulnerabilities in various CMS software and plugins as being exploited by the attackers. These include WordPress, Craft CMS, MaxSite CMS, MetInfo CMS, and Joomla JCE. The list of affected products includes several popular plugins such as Simple File List, WavePlayer, BerqWP, WPBookit, Ninja Forms, ThemeREX Addons, Breeze Cache, pay-uz, ACF Extended, Sneeit Framework, WPvivid Backup, Gravity Forms, and GutenKit/Hunk Companion. Craft CMS and MaxSite CMS have also been targeted.

The ACSC suspects that the attackers may be using artificial intelligence (AI) to support their campaign, which would allow them to accelerate attacks and scale the exploitation of emerging vulnerabilities. This highlights the increasing sophistication of cyber threats and the need for organizations to stay vigilant in the face of such attacks.

To mitigate these risks, website administrators are advised to apply the latest security updates for their CMS, themes, and plugins. They should also remove unused components, enable automatic updates where possible, make web directories read-only when feasible, monitor for unauthorized file creation, restrict access to sensitive directories, and block unexpected spawning of child processes on the web server.

In today’s cyber landscape, it is essential for organizations to test their defenses regularly and stay ahead of potential threats. By taking proactive measures to secure their online presence, businesses can reduce their risk of falling victim to such attacks and protect their customers’ sensitive information.


Source: Bleeping Computer — 2026-07-11