Hackers target WordPress sites via third-party WooCommerce plugin

Refract AI Intelligence Digest

BLUF

Active exploitation of a critical WordPress plugin vulnerability is allowing attackers to gain full site control via PHP backdoors.

NEWS

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin to inject malicious PHP code into WordPress installations. This campaign targets e-commerce sites, allowing attackers to upload backdoors and maintain persistent access.

Why I Care

This impacts all WordPress site owners using the specific WooCommerce plugin, risking data theft, defacement, and loss of customer trust. Successful exploitation grants attackers complete administrative control over the website and potentially the underlying server.

Next Steps

Site administrators using the affected plugin must update to the patched version immediately. If patching is not possible, disable the plugin and scan for existing PHP backdoors within 24 hours.

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.