
If your business runs its own website on WordPress, Joomla, or a similar content management system, there's a real chance it's currently being scanned for a way in. The Australian Signals Directorate's Cyber Security Centre (ACSC) issued a critical alert warning that attackers are running a large-scale, automated campaign against websites worldwide, planting hidden backdoors called webshells on any site running outdated software. Many small and medium Australian businesses have already been affected. Here's what it means and what to check this week.
What's actually happening
A content management system, or CMS, is the software that runs your website behind the scenes; WordPress is the best-known example, but Joomla, Craft CMS and others work the same way. Most CMS platforms rely on plugins for extra features, like contact forms, file uploads or page builders, and those plugins are usually where the trouble starts.
The ACSC says attackers are automatically scanning the internet for websites running CMS software or plugins with known, unpatched vulnerabilities. When they find one, they exploit it to upload a webshell, a small hidden file that gives them ongoing remote access to the site without needing a username or password. From there, they can deface the site, steal data, redirect visitors to scam pages, or use the compromised server as a launchpad to attack other systems.
The alert specifically names WordPress, Craft CMS, MaxSite CMS, MetInfo CMS and Joomla's JCE editor, with vulnerable plugins including Simple File List, WavePlayer and Ninja Forms among those exploited. If your site uses any of these, or you're not certain what it's built on, this is worth a proper look rather than a guess.
Why this matters even for a "simple" brochure website
It's tempting to assume a small, mostly static company website isn't worth a hacker's time. That assumption is exactly what makes this campaign effective, because attackers aren't targeting your business specifically. They're running automated tools that scan millions of sites for the same handful of known flaws, and a five-page brochure site on outdated WordPress plugins is just as vulnerable as a large e-commerce store.
Once a webshell is planted, the damage isn't limited to the website itself. A compromised web server can be used to send phishing emails that look like they come from your domain, host malware that gets served to your own visitors and customers, or act as a stepping stone into other parts of your network if the hosting is shared with other systems. It can also sit there undetected for months, quietly doing none of the above until an attacker decides to use it, which is what makes "we haven't noticed anything wrong" poor evidence that a site is clean.
What to check this week
Confirm your CMS core and every plugin are on the latest version. This is the single biggest factor. If your site was set up once and never touched again, that's the profile this campaign is designed to catch.
Remove plugins you don't actually use. Every inactive plugin is still a potential door if it's ever exploited; deleting the ones you don't need shrinks the target.
Look for anything unfamiliar in your website's file list, particularly newly created files with odd names in upload folders, or files with a recent modification date you can't account for. This isn't always visible without hosting/admin access, so ask whoever manages your site to check if you can't.
Check who has admin access to your CMS, and remove any accounts that shouldn't still be there, particularly from past staff or old contractors.
Confirm you have a recent, working backup of the website, separate from the live server. If a site does turn out to be compromised, restoring from a known-good backup is the cleanest fix; without one, cleanup is far slower and less certain.
If you find anything that looks like a webshell, or your site is already showing odd behaviour like unexpected redirects or unfamiliar admin accounts, the ACSC's guidance is to treat the server as compromised: isolate it, don't just delete the suspicious file and move on, and restore from backup once the vulnerability that let the attacker in has been patched.
The pattern behind this alert
This campaign is a good example of why "set and forget" doesn't work for anything internet-facing, whether that's a website, a firewall, or a piece of on-premises software. Attackers don't need a targeted reason to go after a Perth small business; they need an unpatched, internet-facing system, and automated scanning finds those at scale regardless of who owns them. It's the same logic behind the ASD Essential Eight's emphasis on patching known vulnerabilities within a defined window, just applied to a part of the business, the public website, that often falls outside a company's usual IT support conversation because "someone built it once" and it's rarely thought about again.
If your website was built by a freelancer or agency that's no longer around to maintain it, that's a genuine gap worth closing, not a reason to leave it as-is and hope.
Get it checked
If you're not sure what your website is built on, who last updated it, or whether it's carrying any of the plugins named in this alert, that's a reasonable thing to have looked at properly rather than guess about. Our IT security solutions cover exactly this kind of exposure, alongside the rest of your systems, and our managed IT support keeps software patched proactively so a campaign like this one is a non-event rather than a scramble. Get in touch or call (08) 9325 1196. We've helped Perth businesses stay a step ahead of exactly this kind of threat since 1997.



