Increased Exploitation in Web Content Management Systems

National Cyber Awareness System

US-CERT Current Activity Increased Exploitation in Web Content Management Systems

Original release date: September 21, 2012
Last revised: --

US-CERT is aware of recent increases in the exploitation of known vulnerabilities in web content management systems (CMSs) such as Wordpress and Joomla. Compromised CMS installations can be used to host malicious content.

US-CERT recommends that users and administrators ensure that their CMS installations are patched or upgraded to remove known vulnerabilities.
This may require contacting the hosting provider. Also, users and administrators can check for known vulnerabilities in the National Vulnerability Database by searching their CMS by name.