Chinese‑language hackers leverage new WordPress flaws to pilfer government data in 29 nations
A cyber‑espionage group speaking Mandarin has taken advantage of two freshly disclosed WordPress vulnerabilities, identified as CVE-2026-63030 and CVE-2026-60137, to infiltrate a range of public‑sector and small‑business sites across three dozen countries.
The attackers employed the so‑called “wp2shell” exploit chain, which enables remote code execution on vulnerable WordPress installations. By chaining the two CVEs, the group was able to bypass typical security controls and install back‑door scripts that granted persistent access to compromised servers.
Security monitoring firm GreyNoise reported that the campaign has been observed in 29 distinct nations, with the most significant breach occurring at a Western government agency. Preliminary forensic analysis indicates that the intruders extracted at least 18,566 records containing personally identifiable information, internal communications, and other classified material.
WordPress powers roughly 40 % of all websites, making it an attractive target for threat actors seeking large‑scale impact. The two vulnerabilities were patched earlier this year, but many organizations have delayed updates, leaving legacy installations exposed. Experts stress that the rapid adoption of the exploit suggests the attackers had prior knowledge of the flaws, possibly through a zero‑day purchase or insider leak.
The incident underscores a broader trend of state‑linked actors focusing on open‑source platforms to gather intelligence. While the group’s exact affiliation remains unconfirmed, its operational patterns—use of Chinese language in command‑and‑control traffic and targeting of government entities—mirror tactics observed in previous campaigns attributed to actors with ties to the People’s Republic of China.
Officials from the affected government body have not disclosed the full scope of the data loss, but they confirmed that an internal investigation is underway and that steps are being taken to remediate the compromised WordPress sites. The agency also urged all public‑sector entities to verify that their content management systems are fully patched.
Cybersecurity professionals recommend a multi‑layered response: immediate application of the WordPress security updates, deployment of web‑application firewalls, and continuous monitoring for anomalous activity. Organizations that rely on third‑party plugins should also audit those components, as the “wp2shell” chain can be triggered by vulnerable add‑ons.
As the investigation continues, the episode serves as a reminder that even widely used, ostensibly low‑risk platforms can become vectors for high‑value data exfiltration when attackers exploit unpatched vulnerabilities. Stakeholders are urged to prioritize timely updates and to adopt a proactive posture against emerging threat landscapes.
Comments (0)
Be the first to comment.
Join the discussion