
WP-SHELLSTORM Backdoor Compromises Thousands of WordPress Sites, Exposed Server Reveals
A misconfigured command-and-control server has exposed a widespread WordPress backdoor campaign. The WP-SHELLSTORM malware has infected thousands of sites, granting attackers full access to sensitive data.
An exposed server operated by threat actors has revealed a large-scale campaign targeting WordPress websites through a malicious backdoor called WP-SHELLSTORM. The server, which was left publicly accessible, contained extensive logs and scripts that detail how attackers infiltrate and maintain control over compromised sites.
WP-SHELLSTORM functions as a stealthy backdoor script. Once installed on a WordPress site, it allows attackers to execute arbitrary commands, upload files, modify content, and exfiltrate data without the site owner's knowledge. Evidence from the exposed server indicates that thousands of sites across various sectors have been impacted, from personal blogs to e-commerce platforms.
Infection commonly occurs through outdated plugins, themes, or weak administrator credentials. Attackers may also gain access via compromised FTP accounts or third-party service integrations. Many site owners remain unaware until symptoms appear, such as unexpected redirects, spam injections, or search engine blacklisting.
To protect against such threats, website administrators should apply updates promptly, enforce strong passwords and two-factor authentication, and regularly scan for malware. File integrity monitoring and periodic security audits are also critical for early detection. For site owners seeking a more hands-off security approach, managed WordPress hosting services like AEU Hosting provide continuous monitoring, automated updates, and proactive malware scanning, significantly reducing the risk of undetected backdoors.