Back to Blog
CVE-2026-3844: WordPress Breeze Plugin — Mass Webshell Backdooring (July 2026)
vulnerabilities

CVE-2026-3844: WordPress Breeze Plugin — Mass Webshell Backdooring (July 2026)

breachwire TeamJul 11, 20262 min read

CVE-2026-3844 — WordPress Breeze Plugin

CVE-2026-3844 is a high-severity vulnerability in the WordPress Breeze caching plugin that allows unauthenticated attackers to upload arbitrary files, resulting in persistent webshell backdoors. The flaw is being actively exploited as part of the WP-SHELLSTORM campaign, with over 17,000 confirmed WordPress sites compromised. CVSS score is high; immediate patching is required.

Attack Vector

Attackers scan for WordPress sites running vulnerable versions of the Breeze plugin, exploiting CVE-2026-3844 to upload webshells such as 'down.php'. The SNOWLIGHT dropper is used to automate deployment, and compromised sites are managed via the VShell backdoor, often masquerading under the process name 'kworker/0:2'. Command and control infrastructure has been linked to IP 137.175.93.126. The campaign also leverages other CVEs (CVE-2026-3300, CVE-2026-48907, CVE-2021-29441) to expand access and harvest credentials.

Who Is at Risk

All organizations running WordPress with the Breeze caching plugin are at risk, regardless of hosting environment. Sites with outdated plugins or weak administrative controls are especially vulnerable. At least 25,000 sites show evidence of compromise, with high-value corporate cloud credentials targeted in related attacks. No specific organizations are named, but North American entities are heavily represented in target lists.

Patch & Mitigate

  • Patch: Upgrade Breeze plugin to the latest version released July 2026 or later. Apply all related WordPress and plugin security updates.
  • Workaround: Disable or remove the Breeze plugin if patching is not possible.
  • Detect: Search webroots for unauthorized files (e.g., 'down.php'), monitor for the 'kworker/0:2' process, and review outbound traffic to 137.175.93.126. Audit logs for plugin changes and unexpected admin actions.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers exploit plugin vulnerabilities for initial compromise.
  • TA0005 — Defense Evasion: Webshells and process masquerading (e.g., 'kworker/0:2') evade detection.
  • TA0011 — Command and Control: Persistent outbound connections to attacker infrastructure enable remote management.

Source: https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: