Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilitypersistence-methodwidely-deployed-product-advisory

Mass Exploitation of Critical RCE Flaws in WordPress GutenKit and Hunk Companion Plugins

Updated 3mo agoFirst seen Oct 25, 20253 sources

Hackers have launched a large-scale exploitation campaign targeting WordPress websites using vulnerable versions of the GutenKit and Hunk Companion plugins. Security researchers report that over 8.7 million attack attempts were blocked in just two days, with attackers leveraging three critical vulnerabilities—CVE-2024-9234, CVE-2024-9707, and CVE-2024-11972—to achieve remote code execution (RCE) by installing arbitrary plugins without proper authentication or authorization. Despite patches being released for these flaws in late 2024, a significant number of websites remain unpatched and exposed to these attacks.

Threat actors are distributing a malicious plugin archive named 'up' via GitHub, which contains obfuscated scripts capable of uploading, downloading, and deleting files, as well as changing permissions on compromised sites. One script, disguised as a component of the All in One SEO plugin, enables attackers to automatically log in as administrators, facilitating persistence and further malicious activity. Website owners are urged to update to GutenKit 2.1.1 and Hunk Companion 1.9.0 or later to mitigate the risk of compromise from these ongoing mass exploitation attempts.

Share:
Mass Exploitation of Critical RCE Flaws in WordPress GutenKit and Hunk Companion Plugins
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Oct 25, 20258mo ago

Wordfence reports blocking more than 8.7 million exploit attempts

Security reporting on the campaign said Wordfence blocked over 8.7 million attacks attempting to exploit the old GutenKit and Hunk Companion vulnerabilities. This quantified the scale of the ongoing mass exploitation activity.

Oct 24, 20258mo ago

Attackers launch mass exploitation of unpatched WordPress sites

By late October 2025, attackers were conducting large-scale attacks against WordPress sites running vulnerable versions of GutenKit and Hunk Companion. The campaign focused on exploiting outdated plugin installations rather than newly disclosed flaws.

GutenKit and Hunk Companion vulnerabilities were previously disclosed and patched

The mass exploitation campaign targeted older, already-known flaws in the WordPress plugins GutenKit and Hunk Companion. The references indicate these were outdated vulnerabilities affecting sites that had not applied available fixes.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.