File upload features in common CMS plugins are no longer just a way to store content. In this campaign, unauthenticated upload and editor paths are being used to get PHP to run on the server, so a normal-looking upload becomes code execution and site control.
The ACSC says attackers are actively exploiting flaws in Joomla JCE and WordPress plugins including Ninja Forms - File Uploads, Breeze Cache, and WPvivid Backup & Migration. The Joomla issue is already in CISA KEV and past the patch deadline, which confirms this is active abuse, not a theoretical bug report.
The risk reaches beyond the plugin itself. Once a public site can accept and process attacker-controlled uploads as executable code, the full web server and anything it can reach are in play.