Having faced a mystery, where wordpress/woocommerce shops went nuts, i found out i was hit by the CVE-2026-10795
IOC were:
- Found an "undeletable" mu-plugin:
mu-plugins/turbo-watcher-x.php - 2 plugins got lost:
w3-total-cacheandwoocommerce-german-market - Found a new user admin_{HASH},or adm_{HASH}
- any administrator who logged in, got automatically the same
session_tokensadditionally to it's own login
Secondary IOC was inside options table