Story perspectives
Critical WordPress Vulnerabilities Expose Millions to Attacks
10/28/2025
1 of 1
Story summary
- Threat actors exploit critical vulnerabilities in two WordPress plugins, GutenKit and Hunk Companion, affecting hundreds of thousands of websites.
- Discovered in 2024, the flaws allow unauthenticated attackers to install malicious plugins and run code remotely.
- On October 8, 2025, the exploitation campaign resumed, and Wordfence blocked 8.7 million attempts.
- Dell Technologies disclosed three Storage Manager vulnerabilities with CVSS scores up to 9.8, enabling authentication bypass and data access; organizations should update immediately.
