On 9 July 2026, the Australian Cyber Security Centre (ACSC) issued a critical alert, its highest severity rating, about a global hacking campaign aimed squarely at business websites. Attackers are scanning the internet at massive scale for websites running vulnerable content management systems (CMS) and plugins, then breaking in automatically. The ACSC specifically notes that many small and medium Australian businesses have already been impacted.
If your business website runs on WordPress, or on platforms like Craft CMS or Joomla, this alert applies to you. Here's what's happening, in plain English, and what you should do about it.
What's Actually Happening
Most business websites are built on a CMS, software like WordPress that makes it easy to manage pages and content without coding. These platforms rely heavily on plugins, and plugins are where most of the security holes live.
In this campaign, attackers aren't picking targets. They're running automated scans across the entire internet looking for any website running one of a known list of vulnerable plugins or CMS versions. When they find one, the attack happens in seconds, no human involved. The vulnerabilities being exploited allow things like uploading files without logging in and running code directly on the web server.
Once in, the attackers plant what's called a webshell, a small hidden file that acts like a secret back door. With a webshell in place, they can come back any time and remotely control your web server, even after the original vulnerability is patched.
⚠️ The ACSC also flagged a bigger trend behind this campaign: AI is accelerating how fast attackers weaponise new vulnerabilities. The window between a security flaw being published and it being actively exploited is now shorter than ever, which makes slow patching genuinely dangerous.
What Attackers Do With a Compromised Website
A hijacked business website is more valuable to criminals than most owners realise. According to the ACSC, compromised servers in this campaign are being used for:
- Defacing or disrupting your website, damaging your brand and taking you offline
- Stealing data, including credentials and details your customers enter into forms on your site
- Spreading malware and scams to your visitors, turning your own website into a weapon against your customers
- Pivoting into your business network, using the web server as a stepping stone toward email, files and internal systems
That last point deserves emphasis. Even if your website is "just a brochure," a compromised web server can become the entry point for a much more serious breach of your business.
The Software Being Exploited
The campaign targets known, already-patched vulnerabilities across a range of CMS platforms and plugins. Most are WordPress plugins, many of them extremely common on business websites:
| Software / Plugin | Vulnerability |
|---|---|
| Simple File List (WordPress) | CVE-2025-34085 / CVE-2020-36847 |
| WavePlayer (WordPress) | CVE-2025-12057 |
| BerqWP (WordPress) | CVE-2025-7443 |
| WPBookit (WordPress) | CVE-2025-7852 |
| Ninja Forms (WordPress) | CVE-2026-0740 |
| ThemeREX Addons (WordPress) | CVE-2026-1969 |
| Breeze Cache (WordPress) | CVE-2026-3844 |
| pay-uz (WordPress) | CVE-2026-31843 |
| ACF Extended (WordPress) | CVE-2025-13486 |
| Sneeit Framework | CVE-2025-6389 |
| WPvivid Backup (WordPress) | CVE-2026-1357 |
| Gravity Forms (WordPress) | CVE-2025-12352 |
| GutenKit / Hunk Companion (WordPress) | CVE-2024-9234 (likely) |
| Craft CMS | CVE-2025-32432 |
| MaxSite CMS | CVE-2026-3395 |
| MetInfo CMS | CVE-2026-29014 |
| Joomla JCE | CVE-2026-48907 |
Don't treat this list as exhaustive. The important takeaway is that every one of these flaws is public and has a patch available. Websites are being compromised not because the attacks are sophisticated, but because updates haven't been applied.
What to Do Right Now
-
1
Update everything, today Update your CMS core, every plugin and every theme, and delete any plugins or themes you're not actually using. If a plugin you rely on has an unpatched, actively exploited flaw, disable it until a fix ships.
-
2
Check whether you've already been hit Look for files in your web directories that you didn't put there, especially recently created files in plugin folders. Review web access logs for unexpected POST requests to unfamiliar paths. If you don't know how to do this, ask whoever manages your website to do it, and point them at the ACSC alert.
-
3
If you find a webshell, treat the server as compromised Isolate it, investigate what else the attacker touched, remove the malicious files and any persistence they set up, patch the hole, and restore the site from a known-good backup. Simply deleting the webshell without patching means they'll be back.
-
4
Turn on automatic updates where you can For most business websites, the small risk of a faulty auto-update is far lower than the risk of running a known-vulnerable plugin for weeks. Managed hosting where the provider handles patching is also worth considering.
-
5
Separate your website from your business network Your web server shouldn't have a free path to your internal systems. Blocking unnecessary connections between your website and your corporate network limits how far an attacker can get if the site is breached.
💡 If an agency or provider manages your website: forward them the ACSC alert and ask two direct questions. Are all our CMS and plugin versions current, and have you checked our server for webshells? A good provider will come back with specific answers, not reassurance.
The Bigger Picture for Business Owners
This campaign is a preview of how cyber attacks now work: automated, indiscriminate and fast. Nobody chose to attack your business specifically, your website was simply reachable and unpatched. That's exactly why "we're too small to be a target" no longer holds, the scanning doesn't care how big you are.
The defences that stop this class of attack are unglamorous: rapid patching, removing software you don't use, monitoring for unexpected changes and segmenting your network. This is the bread and butter of managed cyber security, and it's why frameworks like the Essential Eight put patching at the very top of the list.
Reference & Reporting
This article is based on the ACSC's critical alert, which includes the full technical detail and indicators for IT teams: Large-scale exploitation campaign targeting website content management systems (CMS), cyber.gov.au.
If your organisation has been impacted or you suspect a compromise, you can report it and get assistance at cyber.gov.au/report or call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371).
If you'd rather have someone check your website and wider environment for you, BITS can run a security review covering your site, patching posture and network segmentation. Book a free consultation and we'll tell you exactly where you stand.