Chinese-speaking hackers exploited WordPress flaws to breach 49 organizations, steal 18,566 government records, grab credentials, and plant webshells. They also walked off with passwords stored in plaintext. That is the picture from a September 22, 2026 report, and it is ugly in a very ordinary way.
Nobody needed a genius crew for this. They needed WordPress left open and passwords sitting where anyone who got in could read them like a grocery list.
49 organizations, government records, and passwords in the clear
Here is the haul in plain numbers. Attackers hit 49 organizations through WordPress flaws. They stole 18,566 government records. They stole credentials. They planted webshells so they could come back later. And they found passwords in plaintext, which means the logins were readable as typed, not scrambled.
WordPress is not some obscure tool. It is the website software a huge share of regular outfits actually use because it is cheap, familiar, and easy to stand up. Easy to stand up is also easy to neglect. Plugins rot. Core goes unpatched. Some shop or office stores logins the same way you would write them on a sticky note. That is how government records end up in someone else’s hands.
Plaintext passwords are a systems failure
If a site is keeping passwords in plaintext, the rest of the security talk is theater. Once those logins are copied, they get tried on email, payroll, vendor portals, and personal accounts because people reuse the same password everywhere. Mix in 18,566 government records and this stops being an IT headache. It is other people’s information, sitting behind a WordPress site that never got treated like it mattered.
Webshells mean they meant to stay
A webshell is a spare key under the mat. The first hole gets them in. The shell lets them return, poke around, and pull more later. Patching the original WordPress flaw and calling it done is not a cleanup if the backdoor is still on the server.
Anyone running these sites for a town office, a school, a clinic, or a small business needs to hear that part. The break-in is the start of the problem, not the end of it.
What you should do if you run WordPress
This is not a lecture for a corporate security team. This is for the person who actually keeps the website alive.
- Update WordPress core, themes, and every plugin. Old code is the front door in this story.
- Stop storing passwords in plaintext. If a plugin or a custom bit of the site does that, fix it or rip it out.
- Lock down admin logins with unique passwords and two-factor authentication. Reused passwords are how a website breach becomes an email and bank problem.
- After any suspected break-in, hunt for webshells and files that do not belong. Do not assume a patch closed the whole mess.
- If you put government or customer records on WordPress, treat backups, access, and updates like a real job, not a weekend chore.
Regular people did not volunteer to have their government records sitting on a neglected website. The 49 organizations that got hit had one job: keep the door shut. They did not. That should make you mad, and it should make you check your own site before someone else does.
Primary Source: https://cybersecuritynews.com/wordpress-flaws/
