WP-SHELLSTORM Backdoor Found on Exposed Server Hits Thousands of WordPress Sites

WP-SHELLSTORM Backdoor Found on Exposed Server Hits Thousands of WordPress Sites

Security researchers found an exposed criminal server holding a backdoor tool called WP-SHELLSTORM, used to seize control of thousands of WordPress websites. Owners should check their sites immediately.

A threat report published in July 2026 describes an exposed server used by attackers that contained a backdoor tool named WP-SHELLSTORM, along with evidence that the same tool has been used to compromise thousands of WordPress websites. An exposed server in this context means a computer that criminals left reachable on the internet without proper access controls, allowing anyone who found it to inspect its files. The discovery gives website owners a rare look at how attackers maintain hidden control over compromised sites.

WP-SHELLSTORM is described as a backdoor designed specifically for WordPress, the widely used content management system that powers a large share of websites. A web shell or backdoor is a small malicious file placed on a web server; when an attacker opens that file in a browser, it gives them a simple control panel to run commands, upload files, or change the website without needing a normal login. Because WordPress is so common and relies on many third-party plugins, a single vulnerable plugin can let an attacker plant WP-SHELLSTORM on thousands of different sites at once.

For site owners, the most serious consequence of a backdoor like WP-SHELLSTORM is persistence. Even after you change your WordPress admin password, update your plugins, or remove the obvious malware, the backdoor can remain hidden in a folder or inside a legitimate-looking file and continue to give the attacker access. A compromised WordPress site can be used to send spam, host fake banking pages, redirect visitors to scam sites, or attack other websites. Search engines and browsers may then flag the site as dangerous, leading to lost visitors and revenue.

The public disclosure does not name the security researcher or the company that found the exposed server, and it does not say exactly how the backdoor was first installed on each site. But the fact that thousands of WordPress sites are affected should prompt every WordPress owner to act. Check your WordPress installation for administrator accounts you did not create, look for recently changed files in your web hosting file manager, and review your list of installed plugins and themes. Remove anything you no longer use, because old or abandoned plugins are a common entry point. If you are not comfortable doing this yourself, ask your hosting provider or a security professional to run a malware scan.

For owners who want to reduce this risk without becoming security experts, managed WordPress hosting offers a practical layer of protection. AEU Hosting, for example, provides managed WordPress hosting with security built in from end to end, so routine updates, malware scanning, and hardening are handled for you. That kind of service can catch backdoors like WP-SHELLSTORM before they spread, and it gives site owners a clear path to recovery if something does go wrong.

How to Protect Yourself

  1. Log into your WordPress admin area and delete any user accounts you do not recognize, especially those with administrator rights.
  2. Update WordPress itself, all themes, and all plugins right away, and remove any plugin or theme you no longer use.
  3. Change your WordPress password, hosting control panel password, and database password to unique, long phrases, and turn on two-factor authentication if your site supports it.
  4. Ask your hosting provider to run a malware scan or install a reputable WordPress security plugin to scan for WP-SHELLSTORM and other backdoors.
  5. Make a full backup of your site files and database now, so you can restore a clean version if you find an infection.

Related AEU services