Chinese-Speaking Threat Actors Exploit WordPress wp2shell Chain (CVE-2026-63030, CVE-2026-60137) to Steal 18,566 Government Records
A Chinese-speaking threat actor exploited the WordPress wp2shell vulnerability chain (CVE-2026-63030, CVE-2026-60137) to compromise at least 49 organizations across 29 countries, stealing 18,566 records — including plaintext passwords and PII — from a Western…
A Chinese-speaking threat actor (described by one source as suspected) exploited the critical WordPress wp2shell exploit chain, tracked as CVE-2026-63030 and CVE-2026-60137, to compromise government and small-business targets. At least 49 organizations across 29 countries were affected, according to Cyber Security News. From a single Western government organization, the attackers stole 18,566 records including accounts, plaintext passwords, and personally identifiable information. The attack chain was used to deploy webshells, create hidden administrator accounts, and move laterally into internal systems. The same campaign also targeted ZyXEL GS1900 switches, with 996 devices compromised or having sensitive information exfiltrated across 48 countries. Both CVEs have been added to CISA's Known Exploited Vulnerabilities catalog.
- Threat actor identified as Chinese-speaking; Cyber Security News characterizes attribution as suspected, while GBHackers states it directly
- Exploit chain: WordPress wp2shell, tracked as CVE-2026-63030 and CVE-2026-60137
- Both CVEs added to CISA's Known Exploited Vulnerabilities catalog
- At least 49 organizations compromised across 29 countries (per Cyber Security News; GBHackers confirms 29 countries but does not cite the 49-organization count)
- 18,566 records stolen from one Western government organization, including accounts, plaintext passwords, and PII
- Attack techniques: webshell deployment, creation of hidden admin accounts, and lateral movement to internal systems
- ZyXEL GS1900 switches also targeted: 996 devices compromised or with sensitive information exfiltrated across 48 countries
Coverage timelineoldest first · each row is one article
- · 5d agoHackers Exploit WordPress CVE-2026-63030 and CVE-2026-60137 to Steal Government Data
GBHackers· 90
A Chinese threat actor exploited critical WordPress vulnerabilities to steal 18,566 sensitive records from a Western government organization across 29 countries.
- · 4d agoHackers Exploit WordPress Flaws to Steal 18,566 Government Records and Plaintext Passwords
Cyber Security News· 80
Chinese-speaking actor exploited WordPress flaws affecting 49 orgs, stealing 18,566 government records including plaintext passwords.
Vulnerabilities in this storyAll →
- CVE-2026-630309.810%WordPress Core Route Confusion (wp2shell) Enables SQL Injection to RCEpublished · WordPress Core KEV PoC ×3+1 related
| CVE | Vulnerability | CVSS |
|---|