Hackers Are Exploiting Dozens of Known Flaws to Mass-Compromise WordPress, Joomla, and Craft CMS Sites Worldwide
The Australian Cyber Security Centre issued a critical alert on July 9 warning that a global exploitation campaign is actively compromising websites built on WordPress, Joomla, Craft CMS, and several smaller content management platforms. The agency said the attacks are hitting organizations of every size, with small and medium-sized businesses making up a large share of the victims so far, and stressed the campaign is not limited to government or enterprise targets.
According to the ACSC, attackers are systematically scanning the public internet for sites running outdated plugins and extensions, then exploiting known vulnerabilities that allow unauthenticated file uploads, remote code execution, server-side request forgery, or insecure deserialization. Once a weakness is found, the attackers plant a webshell — a small script that gives them persistent, remote control over the server — which can then be used to deface pages, steal credentials, distribute malware, or move deeper into a victim's network.
A related investigation gives a clearer sense of scale. Researchers at SOCRadar and Hunt.io found an exposed, password-free server belonging to a criminal operation now tracked as WP-SHELLSTORM, describing it as a webshell-access brokerage that compromises sites in bulk and resells that access. The toolkit found on the server covered 27 known vulnerabilities across WordPress, Joomla, and other platforms, though only a handful accounted for most of the actual damage. The single biggest contributor was a flaw in the Breeze caching plugin for WordPress, which the operators fired at more than 45,000 targets and used to backdoor upwards of 17,000 sites — a number limited by the fact that the bug only triggers when a specific, non-default setting is enabled. Joomla's Content Editor extension, known as JCE, was the other major entry point; the underlying flaw is rated maximum severity and has been added to the U.S. Cybersecurity and Infrastructure Security Agency's catalog of vulnerabilities under active exploitation.
The operation's target lists, pulled from internet-scanning tools, included roughly 1.4 million domains across WordPress, Joomla, and other software — though that figure reflects sites the attackers scanned or queued for testing, not confirmed victims. A separate analysis of the same leaked data identified a smaller, more conservative number of around 25,000 sites showing actual signs of compromise.
Beyond WordPress and Joomla, the campaign also touches Craft CMS, where a maximum-severity, pre-authentication remote code execution flaw has been circulating since earlier this year, along with smaller platforms such as MaxSite CMS and MetInfo CMS. Separately, Belgium's Centre for Cybersecurity has tracked a related wave of Joomla defacements, tied to a group it calls Trenggalek Cyber Army, exploiting several additional file-upload vulnerabilities in Joomla extensions that were only added to CISA's exploited-vulnerabilities list within the past few weeks.
The ACSC and allied Five Eyes cybersecurity agencies said the speed and scale of the campaign point to attackers increasingly relying on AI-assisted scanning tools, which they warned is shrinking the window organizations have to patch a vulnerability before it's exploited. The agency is advising website administrators to check server logs for unusual activity, disable vulnerable plugins until patches are applied, isolate any system showing signs of a webshell, and restore affected sites from clean backups rather than assuming a patch alone will remove an existing infection.