Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Security

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

The Hacker News · Sep 16, 2026

Back to News
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Security September 16, 2026

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.