{"id":63081,"date":"2026-07-12T09:47:31","date_gmt":"2026-07-12T13:47:31","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=63081"},"modified":"2026-07-12T09:47:31","modified_gmt":"2026-07-12T13:47:31","slug":"acsc-global-cms-campaign","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/acsc-global-cms-campaign\/","title":{"rendered":"ACSC Confirms Global Campaign Targeting Vulnerable CMS"},"content":{"rendered":"<p>The <a href=\"https:\/\/www.cyber.gov.au\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Australian Cyber Security Centre<\/a> (ACSC) has issued an urgent alert confirming a large-scale global exploitation campaign that is actively targeting vulnerable content management systems (CMS) and plugins. The campaign has already impacted numerous <a href=\"https:\/\/overcentral.com\/en\/australian-businesses-cybercrime-burden\/\" title=\"Australian Businesses Bear Growing Cybercrime Burden\" data-iacss-internal=\"1\">Australian businesses<\/a>, particularly small- to medium-sized enterprises, with attackers deploying webshells on compromised websites to establish persistent remote access.<\/p>\n<h2>Widespread Campaign Targets Multiple CMS Platforms and Plugins<\/h2>\n<p>The ACSC reports that malicious actors are systematically scanning websites for exploitable vulnerabilities across a broad range of CMS platforms and popular plugins. The following products and specific CVEs have been identified as targets in this ongoing campaign:<\/p>\n<ul>\n<li>Simple File List (WordPress) \u2013 CVE-2025-34085 \/ CVE-2020-36847<\/li>\n<li>WavePlayer (WordPress) \u2013 CVE-2025-12057<\/li>\n<li>BerqWP (WordPress) \u2013 CVE-2025-7443<\/li>\n<li>WPBookit (WordPress) \u2013 CVE-2025-7852<\/li>\n<li>Ninja Forms (WordPress) \u2013 CVE-2026-0740<\/li>\n<li>ThemeREX Addons (WordPress) \u2013 CVE-2026-1969<\/li>\n<li>Breeze Cache (WordPress) \u2013 CVE-2026-3844<\/li>\n<li>pay-uz (WordPress) \u2013 CVE-2026-31843<\/li>\n<li>ACF Extended (WordPress) \u2013 CVE-2025-13486<\/li>\n<li>Sneeit Framework \u2013 CVE-2025-6389<\/li>\n<li>WPvivid Backup (WordPress) \u2013 CVE-2026-1357<\/li>\n<li>Gravity Forms (WordPress) \u2013 CVE-2025-12352<\/li>\n<li>GutenKit \/ Hunk Companion (WordPress) \u2013 likely CVE-2024-9234<\/li>\n<li>Craft CMS \u2013 CVE-2025-32432<\/li>\n<li>MaxSite CMS \u2013 CVE-2026-3395<\/li>\n<li>MetInfo CMS \u2013 CVE-2026-29014<\/li>\n<li>Joomla JCE \u2013 CVE-2026-48907<\/li>\n<\/ul>\n<p>The list spans widely deployed WordPress plugins, several standalone CMS platforms, and a Joomla editor plugin, reflecting the broad targeting strategy of the threat actors behind the campaign.<\/p>\n<h2>Webshells Provide Persistent Access and Enable Lateral Movement<\/h2>\n<p>Webshells are malicious scripts uploaded to compromised web servers that grant attackers ongoing remote control over the affected environment. Once installed, these backdoors allow threat actors to disrupt website operations, steal user credentials, plant additional malware, and move laterally into the internal network. The ACSC emphasizes that the deployment of webshells represents a significant escalation, as it transforms a single website compromise into a persistent foothold within the organisation&#8217;s broader infrastructure.<\/p>\n<h2>What Is a Webshell and How Does It Compromise a Website?<\/h2>\n<p>A webshell is a malicious script uploaded to a web server that enables an attacker to remotely execute commands, access files, and maintain persistent, covert access to the compromised environment. Unlike a one-time exploit, a webshell gives the attacker ongoing control, often escaping detection by standard <a href=\"https:\/\/overcentral.com\/en\/apple-macos-security-flaw\/\" title=\"Apple macOS Flaw Lets Attackers Disable Security Tools\" data-iacss-internal=\"1\">security tools<\/a>, and serves as a launch point for deeper network infiltration.<\/p>\n<h2>AI-Driven Capabilities May Be Accelerating the Campaign<\/h2>\n<p>The ACSC has noted that the campaign may be supported by artificial intelligence, which would enable threat actors to accelerate scanning, rapidly adapt to newly disclosed vulnerabilities, and scale their exploitation efforts more efficiently. The use <a href=\"https:\/\/overcentral.com\/en\/atlantic-ai-music-training-database\/\" title=\"The Atlantic Releases Searchable Database of AI Music Training Data\" data-iacss-internal=\"1\">of AI<\/a> in this context represents an evolution in the speed and adaptability of mass-exploitation operations, making timely patching even more critical for defenders.<\/p>\n<h2>How Website Administrators Can Protect Against CMS Exploitation<\/h2>\n<p>To defend against this campaign, website administrators should immediately apply the latest security updates for their CMS, themes, and plugins, remove any unused components, and enable automatic updates wherever possible. Additional protective measures include making web directories read-only when feasible, monitoring for unauthorised file creation, restricting access to sensitive directories, and blocking unexpected spawning of child processes on the web server. Deploying a web application firewall with virtual patching capabilities and implementing file integrity monitoring are recommended solution categories that can help detect and block exploitation attempts before webshells are deployed.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Administrators of websites running any of the identified CMS platforms or plugins should treat this alert as an active and urgent threat. Immediately apply all available patches for the listed CVEs, conduct a thorough audit of web directories for any unauthorised files or suspicious scripts, rotate all administrative credentials, and enable multi-factor authentication on all administrative accounts. For organisations that have already detected signs of compromise, engage an incident response team to assess the scope of the breach and remediate any webshells before they can be used to move deeper into the network.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Australian Cyber Security Centre (ACSC) has issued an urgent alert confirming a large-scale global exploitation campaign that is actively targeting vulnerable content management systems (CMS) and plugins. The campaign has already impacted numerous Australian businesses, particularly small- to medium-sized enterprises, with attackers deploying webshells on compromised websites to establish persistent remote access. Widespread Campaign [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74519,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/C1brQUB.jpg","fifu_image_alt":"ACSC Confirms Global Campaign Targeting Vulnerable CMS","footnotes":""},"categories":[349],"tags":[],"class_list":["post-63081","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/C1brQUB.jpg","fifu_image_alt":"ACSC Confirms Global Campaign Targeting Vulnerable CMS","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63081","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=63081"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63081\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74519"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=63081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=63081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=63081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}