Menu
BREAKING NEWS

WordPress Arbitrary Installation Vulnerabilities Exploited in Mass Campaign

Uday Patil Oct 27, 2025 4 min read 72 views
WordPress Arbitrary Installation Vulnerabilities Exploited in Mass Campaign

A critical mass exploitation campaign is actively targeting unpatched content management systems. Security analysts have confirmed that WordPress arbitrary installation vulnerabilities affecting popular plugins GutenKit and Hunk Companion are being aggressively weaponized to achieve remote code execution across thousands of production websites.

With over 8.7 million exploit attempts blocked by web application firewalls, this threat campaign demonstrates the extreme danger of unauthenticated REST API endpoints. Threat actors exploit broken authorization logic to remotely install malicious plugins, deploy persistent webshells, and harvest database credentials. Below is our complete technical breakdown of these WordPress arbitrary installation vulnerabilities and the exact steps required to patch your systems.

WordPress Arbitrary Installation Vulnerabilities: Attack Details & Methods

The root cause behind these WordPress arbitrary installation vulnerabilities stems from improper permission validation within REST API endpoint registrations. Both GutenKit and Hunk Companion implemented permission callbacks that unconditionally return true for incoming web requests, entirely disabling authentication barriers.

In GutenKit, the vulnerable endpoint routes to the install_and_activate_plugin_from_external() function via the gutenkit/v1/install-active-plugin path. Hunk Companion exposes identical unauthenticated functionality through the hc/v1/themehunk-import endpoint.

Adversaries exploit this design flaw by sending automated HTTP POST requests containing external URLs pointing to attacker-controlled ZIP archives. Because the endpoint does not verify user roles or validate package cryptographic signatures, the server downloads and extracts the arbitrary plugin directly into the wp-content/plugins directory.

CVE IdentifierAffected PluginVulnerable VersionsPatched ReleaseCVSS ScoreFlaw Classification
CVE-2024-9234GutenKitVersion 2.1.0 and earlierVersion 2.1.19.8 (Critical)Unauthenticated Arbitrary File Upload
CVE-2024-9707Hunk CompanionVersion 1.8.4 and earlierVersion 1.9.09.8 (Critical)Missing Authorization / Arbitrary Install
CVE-2024-11972Hunk CompanionVersion 1.8.5 and earlierVersion 1.9.09.8 (Critical)REST API Permission Callback Bypass

Malicious Payloads and In-Memory Webshell Deployment

Once attackers trigger these WordPress arbitrary installation vulnerabilities, the deployed archives drop heavily obfuscated PHP backdoors disguised with legitimate metadata headers (such as All in One SEO or standard WordPress core labels) to evade static file scanners.

The malicious packages typically deploy:

  • Base64-Encoded File Managers: Allow attackers to browse, edit, and exfiltrate database configuration files (wp-config.php) directly through the browser.
  • Persistent Web Shells: Grant unauthenticated interactive command execution capabilities on the underlying operating system.
  • Database Rogue Administrators: Inject hidden administrator accounts directly into the wp_users table with elevated capabilities.

To monitor active CMS exploits, zero-day CVEs, and enterprise vulnerability alerts, visit our 2026 Enterprise CVE & Vulnerabilities Security Hub.

Actionable Verification Commands for WordPress Administrators

System administrators and website owners should execute the following command checks across their server environments to audit for unauthorized plugin installations:

  • List recently modified plugin files: find wp-content/plugins/ -type f -mtime -7
  • Inspect WordPress users with administrator role via WP-CLI: wp user list --role=administrator
  • Audit web server logs for exploitation attempts: grep -E "install-active-plugin|themehunk-import" /var/log/nginx/access.log
  • Check for unexpected PHP files in upload directories: find wp-content/uploads/ -name "*.php"

Immediate Mitigation and Remediation Checklist

To neutralize the risk of compromise from these WordPress arbitrary installation vulnerabilities, implement the following security controls immediately:

  • Update Plugins Instantly: Upgrade GutenKit to version 2.1.1 or higher, and update Hunk Companion to version 1.9.0 or higher.
  • Audit Plugin Directories: Manually inspect wp-content/plugins and wp-content/upgrade for unknown or unverified plugin folders.
  • Enforce Web Application Firewall (WAF) Rules: Configure your firewall to block unauthenticated external requests targeting /wp-json/gutenkit/v1/ and /wp-json/hc/v1/ endpoints.
  • Disable File Editing in Dashboard: Add define('DISALLOW_FILE_EDIT', true); to your wp-config.php file to prevent attackers from editing theme and plugin files if an admin account is compromised.

Frequently Asked Questions (FAQ)

What are WordPress arbitrary installation vulnerabilities?

WordPress arbitrary installation vulnerabilities are high-severity security flaws that allow unauthenticated remote attackers to upload, install, and execute unauthorized plugins on a target website by exploiting missing authorization checks in REST API endpoints.

Which plugins are affected by this mass exploit campaign?

The mass campaign specifically targets GutenKit (version 2.1.0 and earlier) and Hunk Companion (version 1.8.5 and earlier), which collectively account for nearly 50,000 active WordPress installations.

How do hackers exploit the GutenKit and Hunk Companion plugins?

Attackers send automated HTTP POST requests to vulnerable REST API endpoints with external download links. Because the permission callback returns true for all users, the server downloads and activates the malicious archive without authentication.

How can website owners detect if their site was compromised?

Check the wp-content/plugins directory for unfamiliar folders, review administrator user accounts for unrecognized emails, and inspect server access logs for requests targeting install-active-plugin or themehunk-import.

This technical vulnerability advisory was authored, tested, and verified by the CyberUpdates365 Threat Intelligence Desk. All mitigation workflows conform to official WordPress security standards and Wordfence Threat Intelligence guidelines as of August 2026.

Uday Patil
About The Author

Uday Patil

Uday Patil is a Cybersecurity Researcher, DevSecOps Engineer, and the Founder of CyberUpdates365. Specializing in Threat Intelligence and Zero-Day vulnerability analysis, Uday is dedicated to breaking down complex cyber threats into actionable insights. His mission is to empower developers, security teams, and aspiring tech talent with rapid alerts, practical guidance, and career mentorship.