
cms-exploitation-campaign
Large Scale Exploitation Campaign against CMS devices reported in July 2026
defensive-toolsintrusion-detectionthreat-intelligence+4
3

Large Scale Exploitation Campaign against CMS devices reported in July 2026

A Wordpress Honeypot

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

Detects shadow-administrator accounts in WordPress via configurable indicators and heuristics, then removes selected accounts through guarded, logged…

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Integrates your Modern Honeypot Network Server and Wordpress Blog via MHN's REST API and WP's shortcodes