Hackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data
A Chinese threat actor exploited critical WordPress vulnerabilities to steal 18,566 sensitive records from a Western government organization across 29 countries.
A Chinese-speaking threat actor exploited the critical WordPress wp2shell vulnerability chain to compromise government and small-business targets across 29 countries, stealing at least 18,566 sensitive records from a Western government organization.
90