Australia warns of global campaign targeting vulnerable CMS platforms
Reported exploitedSimple File ListWavePlayerOur summary
The Australian Cyber Security Centre (ACSC) has issued a warning about a global exploitation campaign targeting vulnerable content management systems (CMS) and related plugins. Attackers are deploying webshells on compromised websites, enabling them to steal data, install malware, and gain deeper access to networks. The ACSC reports that numerous small- to medium-sized businesses in Australia have already been impacted. Affected products include WordPress plugins like Simple File List (CVE-2025-34085), Ninja Forms (CVE-2026-0740), and Breeze Cache (CVE-2026-3844), as well as other CMS platforms such as Craft CMS (CVE-2025-32432) and MetInfo CMS (CVE-2026-29014).
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.