Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

High · The Hacker News ·

WordPress

What happened

Unauthenticated attackers are exploiting a critical flaw in the premium WordPress plugin WooCommerce Wholesale Lead Capture (6,000+ installs) to upload PHP web shells and run code. Sites using it are at risk.

What to do now

Update the plugin to the patched version immediately; if none exists, disable/remove it. Scan uploads and wp-content for PHP web shells, block PHP execution in upload dirs, and review logs for suspicious file writes.

Original source

The Hacker News

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news