One WordPress Exploit Chain Exposed 18,000 Government Records
A compromised WordPress site became the starting point for the theft of more than 18,000 government records, according to GreyNoise. The number comes from one western-government target, not from the entire campaign, but it shows how quickly a website flaw can become a data-loss incident.
GreyNoise calls the technique wp2shell. Attackers chained CVE-2026-63030 and CVE-2026-60137 to gain code execution, establish persistence and search connected systems for valuable information. The researchers linked the activity to at least 49 organisations across 29 countries.
The website was an entry point, not the final target
WordPress is often managed as a publishing system while the information behind it is treated as somebody else’s problem. That boundary disappears after compromise. Application credentials, database connections, cloud tokens, backup locations and trusted network routes can all turn a public-facing site into a bridge towards more sensitive systems.
The reported campaign moved beyond opportunistic probing. GreyNoise observed attempts to identify valuable data, retrieve records and maintain access. Its telemetry does not prove that every targeted organisation lost data, and the report does not establish a complete victim count.
What defenders should investigate now
- Inventory affected components. Identify every WordPress installation, including campaign sites, old microsites and environments owned by agencies or contractors.
- Patch both vulnerabilities. Treat CVE-2026-63030 and CVE-2026-60137 as a chain rather than two unrelated tickets.
- Hunt for persistence. Review recently created or modified PHP files, unfamiliar administrator accounts, scheduled jobs, plugins and changes to configuration files.
- Trace access beyond WordPress. Examine database activity, outbound connections, cloud audit logs and use of secrets stored on the server.
- Rotate exposed credentials. WordPress salts, database passwords, API keys and deployment credentials should be replaced when compromise cannot be excluded.
- Determine what data was reachable. Incident response should answer what the application could query, export or access through adjacent systems.
The hard lesson is not that every WordPress site contains government records. It is that a public website can inherit access to data its owners never intended to expose. Patching closes the known route. Only investigation can show whether somebody already used it.
Sources
- GreyNoise investigation, published 21 September 2026.
- CISA Known Exploited Vulnerabilities catalogue.


