Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
High · Wordfence ·
WordPress
What happened
Critical unauthenticated arbitrary file upload in WooCommerce Wholesale Lead Capture plugin (about 6,000 sites) is being actively exploited, allowing PHP backdoor upload and remote code execution.
What to do now
Update to vendor-patched version immediately; if none, disable/remove plugin. Block PHP uploads, scan wp-content/uploads for webshells, remove malicious files, rotate admin/DB credentials, and review logs. Verify with vendor advisory.
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.