Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Élevé · The Hacker News ·
WordPress
Ce qui s'est passé
Unauthenticated attackers are exploiting a critical flaw in the premium WordPress plugin WooCommerce Wholesale Lead Capture (6,000+ installs) to upload PHP web shells and run code. Sites using it are at risk.
À faire maintenant
Update the plugin to the patched version immediately; if none exists, disable/remove it. Scan uploads and wp-content for PHP web shells, block PHP execution in upload dirs, and review logs for suspicious file writes.
Source originale
Analyse assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.