Inside WP-SHELLSTORM: Uncovering the Infrastructure Targeting Millions of WordPress Sites
Summary
WP-SHELLSTORM is a large-scale webshell access operation that used automated vulnerability scanning, publicly available exploits, and extensive target lists to compromise vulnerable WordPress, Joomla, and other internet-facing websites. The campaign operationalized multiple known vulnerabilities—including CVE-2026-3844 (Breeze WordPress plugin), CVE-2026-48907 (Joomla JCE Editor), CVE-2026-3300 (Everest Forms Pro), CVE-2026-1969 (ThemeREX Addons), CVE-2020-36847 (Simple File List), CVE-2020-25213 (WP File Manager), and CVE-2021-29441 (Alibaba Nacos)—to automate exploitation and deploy persistent webshells. The campaign became visible after an attacker-controlled server was inadvertently exposed without authentication for approximately three weeks, revealing exploit scripts, webshells, scan results, command histories, target lists, and command-and-control configuration data.
The exposed infrastructure contained more than 1.4 million target entries. This figure represents websites selected for scanning rather than confirmed compromises. Researchers reported substantially lower compromise totals, including more than 25,000 sites with validated evidence of compromise and over 5,700 active webshells, depending on the methodology used. The operation demonstrates how attackers can combine known vulnerabilities, automated scanners, and reusable backdoors to build access inventories at scale without relying on zero-day vulnerabilities.
Background of WP-SHELLSTORM
WP-SHELLSTORM is tracked as a webshell access brokerage operation. Instead of compromising websites solely for immediate defacement or data theft, the operators systematically identify vulnerable sites, deploy persistent webshells, validate access, and maintain an inventory that can potentially be used or resold for future malicious activity.
The campaign's internal infrastructure was discovered on a rented server hosted at
137.175.93[.]126. The server reportedly exposed an open directory containing approximately
800 MB of data across 434 files. The material included exploitation frameworks, target
lists, malware components, command histories, webshells, scanning results, and operational configuration
files.
The operators obtained large target lists from internet asset-search platforms and fed them into automated scanners. These scanners fingerprinted websites, identified vulnerable plugin or component versions, and attempted exploitation at scale. When exploitation succeeded, the attacker uploaded a webshell that could execute commands, manipulate files, establish reverse shells, collect credentials, and support deeper compromise of the hosting environment.
Campaign Overview
| Attribute | Details |
|---|---|
| Campaign Name | WP-SHELLSTORM |
| Threat Model | Mass website exploitation and webshell access brokerage |
| Primary Targets | WordPress, Joomla, and other vulnerable internet-facing web applications |
| Target List Size | More than 1.4 million website entries |
| Validated Compromise Estimates | More than 25,000 sites with validated compromise evidence, with another analysis identifying more than 5,700 active webshells |
| Primary Objective | Deploy persistent webshells and establish reusable unauthorized access |
| Initial Access | Exploitation of known vulnerabilities in plugins, extensions, and exposed enterprise applications |
| Primary Backdoor | Obfuscated PHP webshell, including a file identified as down.php |
| Additional Tooling | SNOWLIGHT dropper, VShell backdoor, automated scanners, exploit scripts, and reverse shells |
| Assessed Motivation | Financially motivated access collection and potential resale |
Vulnerability Details
| CVE ID | Affected Product or Component | Vulnerability Type | Campaign Relevance |
|---|---|---|---|
| CVE-2026-48907 | Joomla JCE Editor | Unauthenticated file upload and remote code execution | Targeted at significant scale. Although the campaign recorded relatively few successful compromises through this vulnerability, it remains a critical actively exploited risk. |
| CVE-2020-25213 | WP File Manager WordPress plugin | Unauthenticated remote code execution | A widely exploited legacy vulnerability incorporated into the campaign's mass-scanning toolkit. |
Attack Methodology
-
Phase 1: Target Collection and Fingerprinting
The operators gather large lists of internet-facing websites from public asset-search services and use automated scanners to identify content management systems, installed plugins, exposed paths, component versions, and other indicators of potential vulnerability. -
Phase 2: Vulnerability Matching and Exploitation
Fingerprinting results are compared against the campaign's exploit collection. Automated scripts then target vulnerable plugins, extensions, and web application components to bypass authentication, upload files, modify server-side content, or execute commands. -
Phase 3: Webshell Deployment
After successful exploitation, the attackers upload an obfuscated PHP webshell that provides file management, command execution, reverse-shell access, network scanning, and security-product discovery capabilities. -
Phase 4: Access Validation and Persistence
The operators verify that each deployed webshell remains reachable and functional. Additional payloads, including SNOWLIGHT and VShell, may be installed to maintain persistent access and disguise malicious processes as legitimate Linux kernel worker threads. -
Phase 5: Credential Collection and Internal Discovery
Webshell access is used to inspect configuration files, read databases, collect credentials, retrieve application secrets, identify cloud or payment-related keys, and discover additional systems or services reachable from the compromised server. -
Phase 6: Access Brokerage and Follow-on Abuse
Validated access is retained, organized, transferred, or sold to other threat actors for spam distribution, malware hosting, traffic redirection, credential theft, cryptomining, or deeper intrusion into connected environments.
Indicators of Compromise (IOCs)
Known Infrastructure
Suspicious Webshell Filename Patterns
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Tactic |
|---|---|---|
| T1595.002 | Active Scanning: Vulnerability Scanning | Reconnaissance |
| T1190 | Exploit Public-Facing Application | Initial Access |
| T1505.003 | Server Software Component: Web Shell | Persistence |
| T1059.004 | Command and Scripting Interpreter: Unix Shell | Execution |
| T1105 | Ingress Tool Transfer | Command and Control |
| T1036.004 | Masquerading: Masquerade Task or Service | Defense Evasion |
| T1083 | File and Directory Discovery | Discovery |
| T1046 | Network Service Discovery | Discovery |
| T1552.001 | Unsecured Credentials: Credentials in Files | Credential Access |
| T1005 | Data from Local System | Collection |
| T1071.001 | Application Layer Protocol: Web Protocols | Command and Control |
Visual Attack Flow

Mitigation
-
Patch the Breeze WordPress plugin.
Upgrade Breeze to a version that remediatesCVE-2026-3844. Environments using the non-defaultHost Files Locally – Gravatarsoption should be prioritized because the campaign's exploitation path depended on that setting. -
Update Joomla JCE immediately.
Upgrade JCE Editor to version2.9.99.5or later. Treat systems exposed while running a vulnerable version as potentially compromised and investigate them rather than assuming that patching alone removes an existing webshell. -
Patch all affected WordPress plugins.
Review and update ThemeREX Addons, Everest Forms Pro, Simple File List, Custom CSS JS PHP, BerqWP, Ninja Forms, WavePlayer, WPBookit, WP File Manager, and any other plugin identified in the campaign's exploit inventory. Remove plugins that are unused, abandoned, or no longer supported by their developers. -
Remove unsupported and unnecessary extensions.
Every installed plugin or extension expands the website's attack surface. Disable and delete components that are not operationally required. Do not leave inactive plugins installed, because their vulnerable files may remain reachable from the internet.
Instantly Fix Risks with Saner Patch Management
Saner Patch Management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here .




