Australia sounds the alarm: hackers are hijacking small business websites at scale
The Australian Cyber Security Centre says a worldwide campaign is planting hidden backdoors on sites running WordPress, Joomla, Craft CMS and more, with small businesses bearing the brunt.

Key points
- The Australian Cyber Security Centre (ACSC) warned that a global hacking campaign is breaking into websites built on popular publishing tools, with many small and mid-sized Australian businesses already hit.
- Attackers are planting webshells, small hidden programs that give remote control of a website, on servers they compromise.
- The campaign exploits at least 17 known flaws across WordPress plugins, Craft CMS, MaxSite CMS, MetInfo CMS and Joomla JCE.
- ACSC says artificial intelligence may be helping attackers scan and exploit sites faster than defenders can patch.
- Site owners are told to update every plugin and theme immediately and watch for unfamiliar files on their servers.
Australia's national cyber agency has issued a blunt warning to anyone who runs a website: attackers are scanning the internet at scale, finding out-of-date publishing software, and quietly installing backdoors when they find it. The alert came from the Australian Cyber Security Centre, which sits inside the Australian Signals Directorate, and it names a campaign that is global but has already caught many Australian small and medium businesses. BleepingComputer first reported the advisory.
The targets are content management systems, or CMS platforms, the software packages small businesses use to run websites without writing code. WordPress is by far the best known on the list, which also includes Joomla, Craft CMS, MaxSite and MetInfo.
Once attackers get in, they drop a webshell, a hidden control panel bolted onto the site. From it, a criminal can read files, steal credentials or use the server as a springboard deeper into the business network.
How are the hackers getting in?
They're exploiting known bugs in website plugins that owners haven't patched. Plugins are add-ons that give a WordPress site features like contact forms or file uploads. Each one is a potential door.
The ACSC listed specific flaws being abused. On WordPress alone the list includes Simple File List (CVE-2025-34085 and CVE-2020-36847), WavePlayer (CVE-2025-12057), BerqWP (CVE-2025-7443), WPBookit (CVE-2025-7852), Ninja Forms, ThemeREX Addons, Breeze Cache, pay-uz, ACF Extended (CVE-2025-13486), Sneeit Framework (CVE-2025-6389), WPvivid Backup, Gravity Forms (CVE-2025-12352), and GutenKit/Hunk Companion (CVE-2024-9234). Craft CMS is being hit through CVE-2025-32432, a remote code execution flaw disclosed earlier this year. The Joomla JCE bug, CVE-2026-48907, is one we flagged on 17 June when CISA added it to its exploited-vulnerabilities catalogue at a CVSS score of 10.0.
A CVE ID is simply a public catalogue number for a specific software bug. Each one on that list is a door someone forgot to lock.
This isn't a story about clever new hacking. It's a story about neglected websites. Most of these plugins have patches available. Attackers are simply faster than the site owners.
Was multi-factor authentication any help here?
Not much. MFA on an admin login wouldn't have stopped these attacks. The break-ins are happening through vulnerable code on the public side of the site, not by guessing a password. Different problem, different fix.
ACSC also flags something worth watching: the campaign may be assisted by AI, letting attackers scan more sites and weaponise newly disclosed bugs within hours rather than weeks.
What should site owners actually do?
Update everything today. That means the CMS itself and every plugin. Turn on automatic updates if the platform supports it.
Then do a clean-out. Delete plugins and themes you're not using. Every dormant add-on is an unpatched door.
Admins should make web directories read-only where possible, watch for files appearing that they didn't create, and lock down sensitive folders. If your web server starts launching unexpected processes, treat it as an emergency.
For ordinary customers, the advice is calmer. If you shop on a small business site and start seeing odd payment redirects or unexpected password reset emails, stop and contact the business directly. Use a card with strong fraud protection. And if you reuse passwords across sites, stop.



