Vulnerabilities · 66 days ago

Compromised Sites Become Resale Inventory

The break is not the initial intrusion. The real risk is that a planted webshell can keep a site usable as a commodity asset, so a cleanup that only removes the obvious malware can leave the operator with access they can reuse or sell again. That shifts the problem from one-time compromise to repeat monetization of the same site.

Researchers exposed a WP-SHELLSTORM server and found tools, logs, target lists, and evidence tied to 25,195 validated compromises. The operation targeted outdated WordPress and Joomla plugins, with the biggest activity around the Breeze cache plugin and Joomla's JCE editor.

The exposed material shows a webshell access-brokering model, not just mass exploitation. That means defenders have to think about surviving footholds and reused access, because a site that looks cleaned can still be part of the market if the backdoor or stolen entry point remains.

CVE-2026-48907

NVD KEV

Known exploited · CISA KEV

EPSS 78% (100th percentile).

CISA federal remediation date Jun 19 · date passed

CVE-2026-3844

NVD KEV

CVSS 9.8 CRITICAL: the Breeze Cache plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in… EPSS 28% (98th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-07-10

Editions

Related stories