A large-scale CMS cyber attack is targeting websites that use popular Content Management Systems (CMS), including WordPress, Joomla, Craft CMS, MaxSite CMS, and MetInfo CMS. Attackers are exploiting known CMS security vulnerabilities to install webshells, giving them remote access to compromised websites.
Small and medium-sized businesses are among the most affected. Keeping your CMS, plugins, and themes updated is one of the most effective CMS security best practices to improve website security and protect your business website.
According to the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), many Australian businesses have already been impacted. Website owners should apply the latest security updates, enable website security monitoring, and maintain reliable backups as part of effective website vulnerability management. For more information about this cyberattack campaign, see the official ACSC security alert.
Which CMS Platforms Are Affected?
The campaign targets several widely used Content Management Systems (CMS) and plugins. While WordPress accounts for many of the affected plugins, other CMS platforms are also being actively targeted.
Affected platforms include:
- WordPress
- Craft CMS
- Joomla (JCE)
- MaxSite CMS
- MetInfo CMS
Several WordPress plugins have also been identified as vulnerable, including backup tools, form builders, cache plugins, file management plugins, and theme add-ons.
If your business website uses any of these platforms or plugins, it is important to verify that you are running the latest supported version and have installed all available security updates.
What Is a Webshell?
A webshell is a malicious script uploaded to a compromised website that allows attackers to remotely control the web server. Once installed, a webshell acts like a hidden backdoor, enabling cybercriminals to execute commands, upload files, modify website content, steal data, or install additional malware.
Because webshells often operate silently, businesses may not realise their website has been compromised until customers report unusual behaviour or search engines flag the site as unsafe.
Detecting and removing webshells quickly is essential for maintaining strong website security and preventing further damage.
How Can You Tell If Your Website Has Been Compromised?
A compromised website does not always display obvious warning signs. However, several indicators may suggest malicious activity.
Common warning signs include:
- Unexpected Administrator Accounts – Unknown administrator accounts may indicate that an attacker has gained access to your website. Review all user accounts regularly and remove any that you don’t recognise.
-
Unknown Files on Your Server – New or unfamiliar files in your website folders could be a sign of malware or a webshell. Compare your files with a recent backup or run a security scan.
-
Website Redirects – If visitors are redirected to unfamiliar websites, your CMS may have been compromised. This is often caused by malicious code injected into your website.
-
Slow Website Performance – A sudden drop in website speed or high server usage may indicate malware or other malicious activity running in the background.
-
Browser Security Warnings – Warnings such as “Deceptive Site Ahead” or “This site may be hacked” suggest your website may contain malicious content and should be investigated immediately.
-
Unexpected Plugin or Theme Changes – Plugins, themes, or settings changing without your approval could indicate unauthorised access. Review recent changes and remove anything suspicious.
-
Suspicious Emails – Unexpected emails sent from your domain may indicate that attackers are using your website to send spam or phishing emails.
-
Hosting Provider Security Alerts – If your hosting provider reports unusual activity or malware, investigate the issue immediately and secure your website before restoring normal operation.
If you notice any of these signs, investigate your website immediately and perform a complete malware scan.
Affected Software, Plugins, and CVEs
The following CMS platforms and plugins are known to be targeted in this campaign. If you run any of these, check your version now and patch immediately.
Software / Plugin | CVE |
|---|---|
Simple File List (WordPress) | CVE-2025-34085 / CVE-2020-36847 |
WavePlayer (WordPress) | CVE-2025-12057 |
BerqWP (WordPress) | CVE-2025-7443 |
WPBookit (WordPress) | CVE-2025-7852 |
Ninja Forms (WordPress) | CVE-2026-0740 |
ThemeREX Addons (WordPress) | CVE-2026-1969 |
Breeze Cache (WordPress) | CVE-2026-3844 |
pay-uz | CVE-2026-31843 |
ACF Extended (WordPress) | CVE-2025-13486 |
Sneeit Framework | CVE-2025-6389 |
Craft CMS | CVE-2025-32432 |
MaxSite CMS | CVE-2026-3395 |
MetInfo CMS | CVE-2026-29014 |
Joomla JCE | CVE-2026-48907 |
Most of the affected products are WordPress plugins, underscoring that plugin sprawl — not just the core CMS — is a major attack surface for small business websites.
How to Protect Your Website from CMS Security Vulnerabilities
Protecting your website from CMS security vulnerabilities requires regular maintenance, proactive monitoring, and timely updates. Following CMS security best practices helps reduce the risk of cyberattacks and keeps your CMS, plugins, and themes secure.
- Patch promptly. Every vulnerability in this campaign already has a fix available — the risk exists because sites haven’t updated yet.
- Automate security patching where the risk of a bad patch is low or easily reversible.
- Disable plugins with known, actively exploited vulnerabilities until a fix is applied.
- Use managed cloud hosting where the provider is responsible for patching infrastructure-level vulnerabilities.
- Make web directories read-only where possible, or monitor file creation closely to catch unauthorized uploads fast.
- Restrict file and directory access to only what’s operationally necessary.
- Monitor for unexpected child processes spawned by your web server — a common sign of webshell activity.
- Apply application control on internet-facing servers to limit what software can execute.
- Segment your network so a compromised website can’t be used as a stepping stone into other business systems.
How We Can Help Protect Your Business Website
Keeping your website secure requires more than occasional updates. At IT Solutions in Gippsland, we help businesses across Gippsland reduce the risk of CMS security vulnerabilities through proactive website maintenance, security management, and ongoing technical support. Our goal is to ensure your website remains secure, up to date, and performing reliably.
Our services include:
- Regular CMS, plugin, and theme updates
- Website security monitoring
- Malware and webshell detection
- Website backups and recovery
- Security patch management
- Performance and uptime monitoring
- Website maintenance and technical support
Whether your website runs on WordPress, Craft CMS, Joomla, or another CMS platform, our team can help keep it secure, updated, and performing at its best.
Protect your business website fromsecurity vulnerabilities with expert website maintenance, security updates, and ongoing monitoring.
Frequently Asked Questions
What is a CMS security vulnerability?
What is a webshell?
How can I protect my business website?
Is this a new, unknown ("zero-day") threat?
Should I remove unused plugins?
How do I know if my website has a webshell installed?
Secure Your Website Before Attackers Find It
Protect your website from CMS security vulnerabilities with expert maintenance and security support from IT Solutions in Gippsland.

How Much Does IT Support Cost for a Small Business in Gippsland
Understanding IT support costs in Gippsland helps businesses budget effectively, compare providers, and choose services that provide real value. Looking beyond the initial price helps

Why Cloud Storage Alone Won’t Protect Your Data
For many businesses across Gippsland and regional Victoria, moving to the cloud felt like a major step forward. Platforms like Microsoft 365, Google Workspace, and

How to Plan a Smooth SharePoint Migration in Gippsland
Migrating to SharePoint is not just a technical upgrade — it’s a structural business decision. For many Gippsland businesses, the move to Microsoft 365 has happened gradually. Email moved first.

Dropbox to SharePoint Migration in Gippsland: A Smarter Move for SMEs in 2026
If your business in Gippsland is using Dropbox for file storage, you’re not alone. Many SMEs across Traralgon, Warragul, Sale, Bairnsdale and surrounding areas started with Dropbox because

What Is Zero Trust Security? The New Standard for Australian Small Businesses
In today’s world of constant cyber threats, small businesses in Australia are no longer “too small to hack.”If you’ve ever wondered “How can I make

AEO (AI Engine Optimization): How We Help You Rank in AI Search (2025 Guide)
Artificial Intelligence is reshaping how people search for answers online. Tools like ChatGPT, Perplexity, Gemini, and Copilot are no longer just assisting users—they are becoming