CMSmap is an obfuscated PHP webshell deployed as a malicious WordPress plugin and masquerading as a legitimate security-related component. It has been observed in intrusions exploiting the WordPress Core vulnerability chain known as wp2shell, including CVE-2026-63030 and CVE-2026-60137, where attackers upload rogue plugins to establish persistent access on compromised sites.
The malware functions as a full-featured post-exploitation platform rather than a minimal backdoor. Reported capabilities include password-protected operator access, file management, database access, port scanning, batch code injection, and privilege-escalation modules, including MySQL UDF-based escalation. Its implementation uses heavy obfuscation, including encoded and compressed PHP that is decoded and executed at runtime, consistent with defense-evasion tradecraft intended to hinder analysis and detection.
CMSmap targets WordPress environments running on PHP-enabled web servers and is associated with server-side compromise of self-hosted WordPress instances. Its role in observed attacks is to provide durable remote administration and follow-on exploitation after initial access has already been achieved through vulnerable WordPress REST API functionality. The malware is relevant to defenders monitoring webshell activity, malicious plugin abuse, and post-compromise persistence in WordPress deployments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Webshell 150KB déguisé en plugin WordPress “CMSmap” : plateforme d’attaque complète avec interface graphique, authentification par mot de passe, gestion de fichiers, accès base de données, scan de ports, injection de code en masse, modules d’escalade de privilèges (dont exploitation MySQL UDF).
Webshell 150KB déguisé en plugin WordPress “CMSmap” : plateforme d’attaque complète avec interface graphique, authentification par mot de passe, gestion de fichiers, accès base de données, scan de ports, injection de code en masse, modules d’escalade de privilèges (dont exploitation MySQL UDF).
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A web shell disguised as a legitimate WordPress security plugin, used post-exploitation as a full-featured attack platform for file management, database access, port scanning, code injection, and privilege escalation.
A feature-rich, obfuscated PHP webshell disguised as a WordPress plugin and deployed on compromised servers for persistent remote command execution.
A malicious CMSmap variant deployed as a WordPress plugin/webshell, providing a full attack platform with GUI, password authentication, file management, database access, port scanning, mass code injection, and privilege-escalation modules. It is obfuscated with hex and base64/gzip encoding and decoded at runtime.
A malicious PHP webshell masquerading as a WordPress plugin, providing a graphical interface, password authentication, file management, database access, port scanning, batch code injection, and privilege escalation capabilities.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.