Hackers Exploit WordPress Flaws to Steal 18,566 Government Records and Plaintext Passwords

A suspected Chinese-speaking threat actor has used WordPress vulnerabilities to break into at least 49 organizations across 29 countries. The campaign exposed how a compromised website can become a launchpad for database theft, credential abuse, and wider network intrusion. The attackers exploited the wp2shell chain, tracked as CVE-2026-63030 and CVE-2026-60137, against vulnerable WordPress installations. After […]

This article has been indexed from Cyber Security News

Read the original article: