The Good_WordPress Combolist Quietly Leaked 298 Login Credentials
HEROIC analysts identified a combolist titled Good_WordPress shared on Telegram on 20 March 2026. It contains 298 records, each pairing an email address with a plaintext password and a URL, likely tied to WordPress site logins. Why This Is Dangerous: WordPress accounts often control an entire website, including its content, plugins, and user data. With passwords stored in plaintext, an attacker can log directly into any of these 298 accounts and, depending on the access level, take over the site itself. What Was Exposed: - Email addresses - Plaintext passwords - URLs to the associated WordPress sites Why This Matters: If someone gains access to a WordPress admin account, they can install malicious plugins, redirect visitors, steal customer data, or use the site to host phishing pages, all from a single reused password. Anyone in this file should treat their WordPress login as compromised. How a Combolist Like This Works: Lists labeled Good, like this one, are typically curated by whoever compiled them to indicate the credentials have been checked and confirmed to work, meaning every entry in this file was likely verified as an active login before it was shared. Check If You Are Affected: Use HEROIC's free breach scanner to check your email against more than 400 billion exposed records and find out if your WordPress credentials are part of this or any other leak.
Breach Breakdown
298 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds