Hackers Exploit WordPress Flaws to Steal 18,566 Government Records and Plaintext Passwords
Chinese-speaking actor exploited WordPress flaws affecting 49 orgs, stealing 18,566 government records including plaintext passwords.
A suspected Chinese-speaking threat actor has exploited WordPress vulnerabilities to compromise at least 49 organizations across 29 countries, stealing 18,566 records from a western government including accounts, plaintext passwords, and personally identifiable information. The attackers used the wp2shell exploit chain (CVE-2026-63030 and CVE-2026-60137) to deploy webshells, create hidden admin accounts, and move laterally to internal systems. The campaign also targeted ZyXEL GS1900 switches, with 996 devices compromised or having sensitive information exfiltrated across 48 countries.