If an unknown administrator or plugin that you did not install appeared in your WordPress "by itself" — you are probably a victim of these vulnerabilities. The GutenKit and Hunk Companion plugins (CVE-2024-9234, CVE-2024-9707, CVE-2024-11972, all CVSS 9.8) allow unauthenticated installation of an arbitrary plugin → RCE . Although they were discovered in late 2024, a new massive wave has been ongoing since October 8, 2025 — defense systems blocked 8.7 million attacks in two days .
Are you affected?
- Unknown administrator account that you did not create
- A plugin that "installs itself" — attackers often disguise it as a fake "All in One SEO"
- Unknown
.phpfiles (backdoor) and suspicious scheduled tasks (cron)
What to do now
- Update GutenKit and Hunk Companion to the latest versions (or remove them if you don't use them).
- Delete all unknown admin accounts and change the passwords.
- Find and remove malicious plugins and backdoor files.
- Check the entire system with a scanner — once the admin was created, more could have been added.
This is a textbook example of why "old, outdated plugins" remain the biggest risk for WordPress.
An unknown admin or plugin has appeared? Send us the link — diagnosis is free, and we'll get back to you within 5 minutes. Urgent repair →
WMD — Super fast support.