CyberSecurity News
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
AI summary
Threat actors are taking advantage of a critical security vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin, which has over 6,000 active installations. This flaw allows unauthenticated attackers to upload arbitrary files, including PHP backdoors, enabling them to achieve remote code execution. As a result, attackers can plant PHP web shells on vulnerable systems. Wordfence, a WordPress security company, has blocked over a certain number of attacks, indicating the vulnerability is being actively exploited. The vulnerability poses a significant risk to websites using the affected plugin.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

