A recent cyber threat has implicated a suspected Chinese-speaking actor exploiting the critical WordPress “wp2shell” vulnerability chain, leading to compromises across government entities and small businesses in 29 countries. This breach has resulted in the theft of at least 18,566 sensitive records from one Western government organization, prompting significant concern among authorities regarding the integrity of their data security.
The cybersecurity intelligence firm GreyNoise has been monitoring this malicious activity since early June through its Global Observation Grid, identifying a specific actor linked to a spectrum of attacks. The “wp2shell” attack chain is notable for its combination of two significant flaws within WordPress’s framework: a route-confusion vulnerability within the WordPress REST API batch endpoint, recognized as CVE-2026-63030, and a SQL injection vulnerability associated with the WP_Query component, designated CVE-2026-60137. Together, these vulnerabilities empower an unauthorized actor to execute arbitrary code on susceptible WordPress installations without the requisite plugins or valid credentials, enabling efficient intrusions into even the most defenseless sites.
The affected versions of WordPress include releases from 6.8.x prior to 6.8.6, 6.9.x prior to 6.9.5, and 7.0.x prior to 7.0.2. Fortunately, patches for these critical vulnerabilities were rolled out in versions 6.8.6, 6.9.5, and 7.0.2. Following verified reports of active exploitation, both identified vulnerabilities were cataloged in the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities list on July 21.
According to GreyNoise’s surveillance, at least 49 confirmed organizations have been compromised due to this campaign, impacting government entities in various nations, including Germany, Colombia, Switzerland, Brazil, Japan, the United Kingdom, India, the United States, and Ukraine. Alarmingly, the campaign also reportedly breached a Russian state entity located in Russian-occupied territories of Ukraine, highlighting its far-reaching implications.
The peak of this breach occurred on July 22 when the threat actor targeted a specific Western government organization. Their approach involved exploiting the identified vulnerabilities in WordPress, leading to the deployment of a custom web shell. In a mere 11 minutes, the attacker managed to access the WordPress user table, compromising 13 administrator accounts, which drastically escalated the risk to the organization’s data.
The malicious operator successfully logged into the compromised entity’s WordPress administration panel and created a fraudulent account that mimicked a legitimate organization’s email address. In a cunning attempt to blend in within the organization’s existing account structures, the attacker backdated the registration timestamp of this account to 2025. Subsequently, a custom WordPress plugin was uploaded to facilitate host and application enumeration, enabling the actor to scrutinize critical systems such as Microsoft Defender settings, local user accounts, running services, MySQL installations, and network configurations.
GreyNoise researchers have provided further insight into the actor’s sophisticated tactics, noting that they employed at least 17 different script variants designed to circumvent Microsoft’s Antimalware Scan Interface and test privilege escalation paths. The rapid development of these scripts, often riddled with Chinese-language comments, suggests that a sophisticated language model may have artificially aided in the creation of these tools.
The malicious campaign did not stop at stealing administrative credentials; the actor meticulously extracted sensitive information, such as accounts, plaintext passwords, and personally identifiable information from law enforcement and government agencies. After staging the stolen data into a web-accessible ZIP archive, the operator downloaded the archive, which included vital source code and credentials.
Utilizing the compromised credentials gained through their investigation, the threat actor executed broader attacks against internal resources, successfully accessing an internal SQL database. Subsequently, custom collection tools were employed to bulk-extract information from the server, further exacerbating the severity of the breach.
GreyNoise assesses that this actor aligns closely with, or is part of, the “Red Heron” activity previously documented by Acronis, highlighting similarities in command-and-control infrastructure and malware used. This ongoing campaign has extended its reach beyond WordPress, targeting other platforms such as Ubiquiti UniFi OS, FlowiseAI, and various network devices.
As organizations scramble to fortify their defenses, those running WordPress installations are urged to promptly upgrade to the patched versions and to conduct a thorough investigation for signs of compromise, such as unauthorized administrator accounts or dubious plugins. Given the rapidly evolving threat landscape, it has become evident that public vulnerabilities can swiftly escalate into international data theft crises when exploited applications are interconnected with sensitive internal assets.
