Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

High · Wordfence ·

WordPress

What happened

Critical unauthenticated arbitrary file upload in WooCommerce Wholesale Lead Capture plugin (about 6,000 sites) is being actively exploited, allowing PHP backdoor upload and remote code execution.

What to do now

Update to vendor-patched version immediately; if none, disable/remove plugin. Block PHP uploads, scan wp-content/uploads for webshells, remove malicious files, rotate admin/DB credentials, and review logs. Verify with vendor advisory.

Original source

Wordfence

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news