Vulnerabilities & Exploits · Web App Attack

WordPress Exploit Hit Government Sites Through Default Logins

GreyNoise says a malicious IP has been actively exploiting WordPress flaws CVE-2026-60137 and CVE-2026-63030 to steal more than 18,000 government records, and it found 564 victims still using factory-default credentials. The campaign has been active since early June and turned a web app compromise into a much larger data theft problem.

The attacker gets in through WordPress, then uses out-of-box logins where they still exist to pull data without having to defeat a second barrier. GreyNoise says the collected data was staged through a TFTP, or Trivial File Transfer Protocol, collector, which made bulk exfiltration easier once the foothold was in place.

For government and public-sector WordPress sites, the exposure is not only the CMS flaw itself but any leftover default or legacy admin credentials in the path of the site. If those credentials still unlock adjacent systems, the patch closes one door while leaving the follow-on collection path intact.

2 sources · 13h ago

CVE-2026-60137

NVD KEV

Known exploited · CISA KEV

CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 78% (100th percentile).

CISA federal remediation date Aug 4 · date passed

CVE-2026-63030

NVD KEV

Known exploited · CISA KEV

CVSS 7.5 HIGH: wordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue…

CISA federal remediation date Jul 24 · date passed

Timeline

Sources

Part of the PlainSec briefing for 2026-09-21

Every edition of this story: WordPress Exploit Hit Government Sites Through Default Logins

More from today