CVE Tools

Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites

The Hacker NewsBy The Hacker News

Reported exploitedWordPressJoomla

Our summary

A cybercriminal group accidentally left a server exposed online for three weeks, revealing internal operations including tools, logs, and a list of over 1.4 million targeted websites. Researchers identified the campaign as WP-SHELLSTORM, where attackers exploit outdated plugins to plant webshells on vulnerable WordPress and Joomla sites. The most impactful flaws were in the Breeze caching plugin (CVE-2026-3844) and the Joomla JCE editor (CVE-2026-48907). These vulnerabilities allowed attackers to gain unauthorized access and control over compromised systems. Website owners using these platforms should prioritize patching affected components immediately.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store