CVE-2026-60137
Known exploited · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 78% (100th percentile).
CISA federal remediation date Aug 4 · date passed
Vulnerabilities & Exploits · Web App Attack
GreyNoise says a malicious IP has been actively exploiting WordPress flaws CVE-2026-60137 and CVE-2026-63030 to steal more than 18,000 government records, and it found 564 victims still using factory-default credentials. The campaign has been active since early June and turned a web app compromise into a much larger data theft problem.
The attacker gets in through WordPress, then uses out-of-box logins where they still exist to pull data without having to defeat a second barrier. GreyNoise says the collected data was staged through a TFTP, or Trivial File Transfer Protocol, collector, which made bulk exfiltration easier once the foothold was in place.
For government and public-sector WordPress sites, the exposure is not only the CMS flaw itself but any leftover default or legacy admin credentials in the path of the site. If those credentials still unlock adjacent systems, the patch closes one door while leaving the follow-on collection path intact.
2 sources · 13h ago
Known exploited · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 78% (100th percentile).
CISA federal remediation date Aug 4 · date passed
Known exploited · CISA KEV
CVSS 7.5 HIGH: wordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue…
CISA federal remediation date Jul 24 · date passed
Cybersecurity Dive
China-nexus actor steals thousands of documents in monthslong exploitation campaign
Researchers suspect the hacker employed LLMs to develop custom tools.
originalGreyNoise Labs
Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation
We detail a few of the more notable intrusions we observed including the theft of more than 18,000 sensitive records from a western government.
originalPart of the PlainSec briefing for 2026-09-21
Every edition of this story: WordPress Exploit Hit Government Sites Through Default Logins