Attackers targeted multiple widely used WordPress plugins with critical flaws that enabled site takeover, malware deployment, and remote code execution. The most prominent issue, CVE-2024-27956 in WP-Automatic before version 3.9.2.0, was exploited through SQL injection to bypass authentication, create rogue administrator accounts, upload malicious files, and fully compromise websites; defenders were told to watch for suspicious admin usernames beginning with xtw, renamed WP-Automatic files, and known malicious file hashes. CSIRT.SK also reported more than 5.5 million exploitation attempts across several WordPress plugin vulnerabilities, including CVE-2024-27956, CVE-2024-2876, CVE-2024-2417, and CVE-2024-28890.
Separate advisories warned that Forminator versions earlier than 1.29.3 contained a critical unrestricted file upload flaw, CVE-2024-28890, that could let remote attackers execute code on the server, alongside CVE-2024-31077 and CVE-2024-31857, which exposed sites to SQL injection and cross-site scripting. CSIRT.SK also flagged Poll Maker before version 3.4 for CVE-2024-32514, an arbitrary file upload vulnerability that could lead to remote code execution. The combined disclosures showed active attacker focus on vulnerable WordPress plugins as an initial access path, prompting urgent patching and compromise checks across exposed sites.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK warned about critical vulnerabilities in the WP-Automatic and Poll Maker WordPress plugins, including CVE-2024-27956 and CVE-2024-32514. The advisory said more than 5.5 million active exploitation attempts had been observed across several plugin vulnerabilities and shared indicators of compromise.
WPScan published a report on a new malware campaign targeting the WP-Automatic plugin. The reference establishes public reporting of the campaign but does not provide an explicit event date beyond the publication itself.
CSIRT.SK reported three vulnerabilities in the WordPress Forminator plugin, including critical CVE-2024-28890 and high-severity CVE-2024-31077 and CVE-2024-31857. The notice said versions earlier than 1.29.3 were affected and recommended upgrading to 1.29.3 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcewpscan.com
Open sourcecsirt.sk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.