The ‘WordPress’ Combolist: 8,135 Site Login Credentials Leaked
In April 2026, HEROIC analysts identified a combolist file labeled WordPress uploaded by a Telegram user, containing 8,135 records of email addresses and plaintext passwords tied to WordPress site logins. Why This Is Dangerous: A working WordPress login can give an attacker full administrative control over a website, including the ability to install malicious plugins, redirect visitors, steal customer data, or use the site to host phishing pages and malware. With over 8,000 accounts in this file, the potential for widespread site compromise is significant. What Was Exposed: - Email addresses tied to WordPress accounts - Plaintext passwords - URLs of the affected WordPress login pages Why This Matters: Website administrators often reuse the same login across their WordPress dashboard, hosting account, and email, meaning a single leaked credential can cascade into a much larger compromise. Visitors to an affected site are also at risk if attackers use admin access to inject malicious code. How This Combolist Works: Lists like this are typically built by scanning the internet for WordPress login pages and testing stolen or previously leaked credentials against them. Successful logins are compiled into a labeled file, in this case one specifically advertising WordPress access, making it attractive to buyers looking to compromise websites at scale. Check If You Are Affected: If you manage a WordPress site, check your admin credentials against HEROIC's free breach scanner, which searches more than 400 billion exposed records, to see if you are affected.
Breach Breakdown
8,135 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds