← All stories
● Covered by 1 source · 1 reportHigh impact

Hacker Server Leak Exposes WP-SHELLSTORM's Backdoor Operations on WordPress Sites

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • WP-SHELLSTORM targeted outdated WordPress plugins
  • Over 1.4 million websites were listed as potential targets
  • CVE-2026-3844 bug affected over 45,000 sites
  • Server was left exposed for 22 days

Overview of the Incident

A cybercrime crew, identified as WP-SHELLSTORM, accidentally exposed one of their servers for three weeks. This incident unveiled their hacking tools and logs, showing their operations against WordPress sites. Although the target list contained 1.4 million sites, they were not all successfully hacked.

Details of the Exposed Server

The server, located at 137.175.93[.]126, was found by security teams due to its lack of basic password protection. Inside, approximately 800MB of files was publicly accessible, including webshells, exploit scripts, and command history. This careless leak was due to the operator running a Python web server for file transfers without securing it.

Exploitation of Vulnerabilities

WP-SHELLSTORM utilized known vulnerabilities in outdated plugins to launch automated attacks against a large number of websites. Their primary target was the Breeze caching plugin, specifically exploiting CVE-2026-3844, which allowed them to backdoor more than 17,000 sites when certain conditions were met.

Implications for the WordPress Community

This incident serves as a critical reminder for website administrators to regularly update their plugins to mitigate risks from such mass hacking operations. The findings also underline the importance of monitoring and securing web servers to avoid similar exposures in the future.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A cybercrime group operating under the name WP-SHELLSTORM left a server open, revealing over 1.4 million targeted websites and operational details of their mass hacking approach. This exposure highlights significant vulnerabilities in outdated WordPress plugins, particularly affecting users of the Breeze caching plugin and Joomla's JCE editor.