Attackers Exploit WordPress Plugin Vulnerabilities for Remote Code Execution and Webshell Access
ID: c9b02315-d16c-5135-af5a-d7fc57466434
STIX ID: report--c9b02315-d16c-5135-af5a-d7fc57466434
Feed Name: GBHackers
A large-scale active exploitation campaign is weaponising known vulnerabilities across multiple CMS platforms—primarily WordPress plugins—to deploy webshells and obtain persistent remote access. Adversaries scan for vulnerable sites and chain unauthenticated file uploads, RCE, SSRF and deserialization flaws to install webshells used for command execution, lateral movement, data exfiltration, and hosting scams; the report lists affected plugins and CVEs and urges immediate patching, inspection of web directories and logs, isolation of compromised servers, and hardening to reduce blast radius.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
