
criticalCyber Attacks
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin, a premium WordPress plugin with over 6,000 active installs. The flaw allows unauthenticated attackers to upload arbitrary files, including PHP web shells, leading to remote code execution. Wordfence has blocked exploitation attempts and urges users to apply patches immediately.
The Hacker News2 min read