I believe there is a vulnerability in the User Portal wordpress_manager module and or addons module/wp_autologin feature.
I've been watching for sh command execution using falco. I got notified today that two of my CWP user accounts ran sh -c chown : /home/username/public_html/cwp_login_xxxxx.php
And there were new cwp_login_xxxxx.php files created in both these user directories.
I guess these kinds of files are generated by CWP to allow the user to bypass their Wordpress login. Idk, never used that feature.
I'm the only one that has access to these users, and this was triggered from an IP I don't use. 155.117.252.20And these sites don't have Wordpress, or any active website for that matter, so impossible for an attack to have come through Wordpress.
I did this to check around the time that the cwp_login files were created.
grep -E "16:1[4-6]:" /usr/local/cwpsrv/logs/access_log
And got this:
155.117.252.20 - - [03/Sep/2026:16:15:15 -0600] "POST /user1/index.php?module=addons&act=wp_autologin HTTP/1.1" 302 89 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:15 -0600] "POST /user1/index.php?module=wordpress_manager&acc=list_domains HTTP/1.1" 302 160 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:15 -0600] "POST /user2/index.php?module=addons&act=wp_autologin HTTP/1.1" 302 90 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:15 -0600] "POST /user2/index.php?module=wordpress_manager&acc=list_domains HTTP/1.1" 302 160 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:16 -0600] "POST /user2/index.php?module=wordpress_manager&acc=list_domains HTTP/1.1" 302 160 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:16 -0600] "POST /user2/index.php?module=wordpress_manager&acc=scan_installations HTTP/1.1" 302 121 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:17 -0600] "POST /user2/index.php?module=domains&acc=dirlist HTTP/1.1" 302 12 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:17 -0600] "POST /user2/index.php?module=wordpress_manager&acc=list_domains HTTP/1.1" 302 160 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:18 -0600] "POST /user2/index.php?module=domains&acc=dirlist HTTP/1.1" 302 12 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:18 -0600] "POST /user2/index.php?module=domains&acc=dirlist HTTP/1.1" 302 12 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:18 -0600] "POST /user2/index.php?module=letsencrypt&acc=list HTTP/1.1" 302 14 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:19 -0600] "POST /user2/index.php?module=addons&act=wp_autologin HTTP/1.1" 302 90 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:19 -0600] "POST /user2/index.php?module=git_manager&acc=list_repos HTTP/1.1" 302 12 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:20 -0600] "POST /user2/index.php?module=addons&act=wp_autologin HTTP/1.1" 302 94 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:21 -0600] "POST /user1/index.php?module=wordpress_manager&acc=list_domains HTTP/1.1" 302 160 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:21 -0600] "POST /user1/index.php?module=wordpress_manager&acc=scan_installations HTTP/1.1" 302 121 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:22 -0600] "POST /user1/index.php?module=domains&acc=dirlist HTTP/1.1" 302 12 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:22 -0600] "POST /user1/index.php?module=wordpress_manager&acc=list_domains HTTP/1.1" 302 160 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:23 -0600] "POST /user1/index.php?module=domains&acc=dirlist HTTP/1.1" 302 12 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:23 -0600] "POST /user1/index.php?module=domains&acc=dirlist HTTP/1.1" 302 12 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:24 -0600] "POST /user1/index.php?module=addons&act=wp_autologin HTTP/1.1" 302 89 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:24 -0600] "POST /user1/index.php?module=git_manager&acc=list_repos HTTP/1.1" 302 12 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:24 -0600] "POST /user1/index.php?module=letsencrypt&acc=list HTTP/1.1" 302 14 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
155.117.252.20 - - [03/Sep/2026:16:15:25 -0600] "POST /user1/index.php?module=addons&act=wp_autologin HTTP/1.1" 302 93 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
These times lineup exactly when falco logged that "sh -c chown : /home/user1/public_html/cwp_login_xxxxxx.php" was ran so somehow this IP was able to POST data in a way that bypassed auth and allowed these wordpress login bypass files to be created by CWP.
I would block access to 2082 & 2083, (obvs admin 2086 / 2087 and 2030 / 2031, and API 2304 should already be whitelist only) until CWP can release a patch.