Drooid Logo
Back to today’s briefing

Story perspectives

Critical WordPress Vulnerabilities Expose Millions to Attacks

10/28/2025

30 5 Full Breakdown

1 of 1

Story summary
  • Threat actors exploit critical vulnerabilities in two WordPress plugins, GutenKit and Hunk Companion, affecting hundreds of thousands of websites.
  • Discovered in 2024, the flaws allow unauthenticated attackers to install malicious plugins and run code remotely.
  • On October 8, 2025, the exploitation campaign resumed, and Wordfence blocked 8.7 million attempts.
  • Dell Technologies disclosed three Storage Manager vulnerabilities with CVSS scores up to 9.8, enabling authentication bypass and data access; organizations should update immediately.