CMS Security Vulnerabilities: How to Protect Your Business Website from Active Cyber Threats

cms-security-vulnerabilities

A large-scale CMS cyber attack is targeting websites that use popular Content Management Systems (CMS), including WordPress, Joomla, Craft CMS, MaxSite CMS, and MetInfo CMS. Attackers are exploiting known CMS security vulnerabilities to install webshells, giving them remote access to compromised websites.

Small and medium-sized businesses are among the most affected. Keeping your CMS, plugins, and themes updated is one of the most effective CMS security best practices to improve website security and protect your business website.

According to the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), many Australian businesses have already been impacted. Website owners should apply the latest security updates, enable website security monitoring, and maintain reliable backups as part of effective website vulnerability management. For more information about this cyberattack campaign, see the official ACSC security alert.

CMS Security Vulnerabilities ASCS

Which CMS Platforms Are Affected?

The campaign targets several widely used Content Management Systems (CMS) and plugins. While WordPress accounts for many of the affected plugins, other CMS platforms are also being actively targeted.

Affected platforms include:

  • WordPress
  • Craft CMS
  • Joomla (JCE)
  • MaxSite CMS
  • MetInfo CMS

Several WordPress plugins have also been identified as vulnerable, including backup tools, form builders, cache plugins, file management plugins, and theme add-ons.

If your business website uses any of these platforms or plugins, it is important to verify that you are running the latest supported version and have installed all available security updates.

What Is a Webshell?

A webshell is a malicious script uploaded to a compromised website that allows attackers to remotely control the web server. Once installed, a webshell acts like a hidden backdoor, enabling cybercriminals to execute commands, upload files, modify website content, steal data, or install additional malware.

Because webshells often operate silently, businesses may not realise their website has been compromised until customers report unusual behaviour or search engines flag the site as unsafe.

Detecting and removing webshells quickly is essential for maintaining strong website security and preventing further damage.

How Can You Tell If Your Website Has Been Compromised?

A compromised website does not always display obvious warning signs. However, several indicators may suggest malicious activity.

Common warning signs include:

  1. Unexpected Administrator Accounts – Unknown administrator accounts may indicate that an attacker has gained access to your website. Review all user accounts regularly and remove any that you don’t recognise.
  2. Unknown Files on Your Server – New or unfamiliar files in your website folders could be a sign of malware or a webshell. Compare your files with a recent backup or run a security scan.

  3. Website Redirects – If visitors are redirected to unfamiliar websites, your CMS may have been compromised. This is often caused by malicious code injected into your website.

  4. Slow Website Performance – A sudden drop in website speed or high server usage may indicate malware or other malicious activity running in the background.

  5. Browser Security Warnings – Warnings such as “Deceptive Site Ahead” or “This site may be hacked” suggest your website may contain malicious content and should be investigated immediately.

  6. Unexpected Plugin or Theme Changes – Plugins, themes, or settings changing without your approval could indicate unauthorised access. Review recent changes and remove anything suspicious.

  7. Suspicious Emails – Unexpected emails sent from your domain may indicate that attackers are using your website to send spam or phishing emails.

  8. Hosting Provider Security Alerts – If your hosting provider reports unusual activity or malware, investigate the issue immediately and secure your website before restoring normal operation.

If you notice any of these signs, investigate your website immediately and perform a complete malware scan.

Affected Software, Plugins, and CVEs

The following CMS platforms and plugins are known to be targeted in this campaign. If you run any of these, check your version now and patch immediately.

Software / Plugin
CVE
Simple File List (WordPress)
CVE-2025-34085 / CVE-2020-36847
WavePlayer (WordPress)
CVE-2025-12057
BerqWP (WordPress)
CVE-2025-7443
WPBookit (WordPress)
CVE-2025-7852
Ninja Forms (WordPress)
CVE-2026-0740
ThemeREX Addons (WordPress)
CVE-2026-1969
Breeze Cache (WordPress)
CVE-2026-3844
pay-uz
CVE-2026-31843
ACF Extended (WordPress)
CVE-2025-13486
Sneeit Framework
CVE-2025-6389
Craft CMS
CVE-2025-32432
MaxSite CMS
CVE-2026-3395
MetInfo CMS
CVE-2026-29014
Joomla JCE
CVE-2026-48907

Most of the affected products are WordPress plugins, underscoring that plugin sprawl — not just the core CMS — is a major attack surface for small business websites.

How to Protect Your Website from CMS Security Vulnerabilities

Protecting your website from CMS security vulnerabilities requires regular maintenance, proactive monitoring, and timely updates. Following CMS security best practices helps reduce the risk of cyberattacks and keeps your CMS, plugins, and themes secure.

  • Patch promptly. Every vulnerability in this campaign already has a fix available — the risk exists because sites haven’t updated yet.
  • Automate security patching where the risk of a bad patch is low or easily reversible.
  • Disable plugins with known, actively exploited vulnerabilities until a fix is applied.
  • Use managed cloud hosting where the provider is responsible for patching infrastructure-level vulnerabilities.
  • Make web directories read-only where possible, or monitor file creation closely to catch unauthorized uploads fast.
  • Restrict file and directory access to only what’s operationally necessary.
  • Monitor for unexpected child processes spawned by your web server — a common sign of webshell activity.
  • Apply application control on internet-facing servers to limit what software can execute.
  • Segment your network so a compromised website can’t be used as a stepping stone into other business systems.
 
If a third party manages your website, share this alert with them and confirm they’re taking these steps on your behalf.

How We Can Help Protect Your Business Website

Keeping your website secure requires more than occasional updates. At IT Solutions in Gippsland, we help businesses across Gippsland reduce the risk of CMS security vulnerabilities through proactive website maintenance, security management, and ongoing technical support. Our goal is to ensure your website remains secure, up to date, and performing reliably.

Our services include:

Whether your website runs on WordPress, Craft CMS, Joomla, or another CMS platform, our team can help keep it secure, updated, and performing at its best.

Protect your business website fromsecurity vulnerabilities with expert website maintenance, security updates, and ongoing monitoring.

Frequently Asked Questions

What is a CMS security vulnerability?

A CMS security vulnerability is a weakness in a content management system or plugin that attackers can exploit to gain unauthorised access, install malware, or compromise a website.

What is a webshell?

A webshell is a malicious script planted on a compromised web server that gives an attacker ongoing remote access and control — effectively a hidden backdoor into the site.

How can I protect my business website?

Keep your CMS, plugins, and themes updated, enable multi-factor authentication, monitor website activity, perform regular security scans, and maintain secure backups.

Is this a new, unknown ("zero-day") threat?

No. Every vulnerability listed in this campaign is publicly known and already has a patch available. The risk comes from unpatched, out-of-date software — not undiscovered flaws.

Should I remove unused plugins?

Yes. Unused plugins increase your attack surface and should be removed if they are no longer needed.

How do I know if my website has a webshell installed?

Check your web directories for unfamiliar or recently modified files, review access logs for unusual requests, and look for unexpected child processes running from your web server.

Secure Your Website Before Attackers Find It

Protect your website from CMS security vulnerabilities with expert maintenance and security support from IT Solutions in Gippsland.