Hackers Scan CMS Websites Globally to Deploy Webshells and Steal Credentials

A large-scale cyber exploitation campaign is actively targeting Content Management System (CMS) websites worldwide. Cybercriminals are aggressively scanning web servers to find unpatched software and vulnerable plugins.

By exploiting these weaknesses, attackers deploy malicious webshells to gain remote control over compromised websites. This campaign has impacted numerous organizations globally, including a significant number of small- to medium-sized businesses.

The rapid scale of these attacks highlights a growing trend recently recognized by the Five Eyes cybersecurity agencies. Threat actors are increasingly leveraging artificial intelligence to accelerate cyber operations.

This technological shift drastically shrinks the critical window between a vulnerability’s public disclosure and its active exploitation in the wild.

Hackers Exploit CMS Websites

When malicious actors identify a vulnerable CMS, they target specific flaws to breach the system.

These vulnerabilities primarily allow unauthenticated file uploads, remote code execution, server-side request forgery, or unsafe deserialization.

Once these exploits succeed, the attackers deploy a webshell that serves as a hidden backdoor into the system.

Software / PluginCVE Identifier(s)
Simple File List (WordPress)CVE-2025-34085 / CVE-2020-36847
WavePlayer (WordPress)CVE-2025-12057
BerqWP (WordPress)CVE-2025-7443
WPBookit (WordPress)CVE-2025-7852
Ninja Forms (WordPress)CVE-2026-0740
ThemeREX Addons (WordPress)CVE-2026-1969
Breeze Cache (WordPress)CVE-2026-3844
pay-uz (WordPress)CVE-2026-31843
ACF Extended (WordPress)CVE-2025-13486

With a webshell active, hackers can remotely command the targeted web server. Attackers leverage this unauthorized access to deface websites, disrupt normal business operations, and capture sensitive user credentials stored on the server.

Furthermore, compromised web servers are frequently used to host and distribute additional malware to scam legitimate visitors or serve as a covert pathway for broader corporate network compromise.

Organizations must act quickly to detect potential compromises and secure their digital infrastructure.

The Australian Signals Directorate’s Australian Cyber Security Center (ASD’s ACSC) strongly advises website administrators to inspect their CMS environments proactively, cyber said.

As threat actors continue to weaponize AI and automate their scanning capabilities, the window for manual remediation is closing faster than ever.

Organizations must transition from reactive patching to proactive defense, prioritizing continuous monitoring and rapid, automated security updates.

By hardening CMS environments, enforcing strict access controls, and closely monitoring web server processes, businesses can effectively break the attack chain and protect their infrastructure from these aggressive global exploitation campaigns.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories