The issue with old WordPress plugins
Your website is more than a digital storefront, it’s an asset that threat actors actively target. Recently, a large-scale exploitation campaign has exposed how dangerous unpatched WordPress plugins really are.
New Real-World Threat: Mass Exploitation Campaign
A recent wave of attacks is exploiting critical vulnerabilities in two popular WordPress plugins: GutenKit and Hunk Companion.
- Security firm Wordfence reported 8.7 million blocked attack attempts within just two days.
- The exploited issues include:
- CVE-2024-9234 (GutenKit) an unauthenticated REST endpoint allowing attackers to install arbitrary plugins.
- CVE-2024-9707 and CVE-2024-11972 (Hunk Companion) missing authorisation in a REST endpoint, also facilitating arbitrary plugin installs.
- These flaws can lead to remote code execution (RCE): attackers can install malicious plugins, gain persistence, and take over sites.
- Even though patches for these vulnerabilities (GutenKit 2.1.1 and Hunk Companion 1.9.0) have existed since late 2024, many sites remain unpatched.
Why Outdated Plugins = Danger
This isn’t theoretical, it’s happening at scale. Failing to update plugins can result in:
- Full site compromise: Attackers can add backdoors, upload files, or execute code through malicious plugins.
- Persistent access: Threat actors use obfuscated scripts hosted in plugin files (e.g. a malicious “up” plugin) to maintain control.
- Unauthorised admin access: The attackers disguise parts of their payload to look like legitimate plugins (e.g., All-in-One SEO components), allowing automatic login as admin.
- Stealthy compromise: Indicators of compromise include specific REST API paths (
/wp-json/gutenkit/v1/install-active-plugin or /wp-json/hc/v1/themehunk-import) and rogue directories like /up or /wp-query-console.
How Technicalities Can Help
Preventing attacks is not just about updating plugins, it’s about proactive, expert-led maintenance. At Technicalities, we provide:
- Comprehensive Plugin Audits
- We scan your WordPress site for outdated or vulnerable plugins, including known high-risk ones like GutenKit and Hunk Companion.
- Security Hardening
- We apply the latest patches, remove unused or risky plugins, and configure REST endpoints safely.
- Continuous Monitoring & Alerts
- We watch for signs of compromise (suspicious API calls, new plugin installs, rogue directories) and alert you immediately.
- Ongoing Maintenance
- Regular updates, scheduled backups, and compatibility checks give you peace of mind, and protect your site from evolving threats.
Key Takeaways
- This is a real and active threat, according to WordPress security firm Wordfence, millions of exploit attempts hit WordPress sites in just days.
- Vulnerabilities in GutenKit and Hunk Companion enable attackers to install plugins and run arbitrary code
- Updating is urgent. Even though fixes have existed for over a year, many sites remain exposed.
- Technicalities’ audit and maintenance services help identify risk, patch issues, and keep your site proactively secure.