Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Élevé · The Hacker News ·

WordPress

Ce qui s'est passé

Unauthenticated attackers are exploiting a critical flaw in the premium WordPress plugin WooCommerce Wholesale Lead Capture (6,000+ installs) to upload PHP web shells and run code. Sites using it are at risk.

À faire maintenant

Update the plugin to the patched version immediately; if none exists, disable/remove it. Scan uploads and wp-content for PHP web shells, block PHP execution in upload dirs, and review logs for suspicious file writes.

Source originale

The Hacker News

Analyse assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber