Hackers target WordPress sites via third-party WooCommerce plugin
BLUF
Active exploitation of a critical WordPress plugin vulnerability is allowing attackers to gain full site control via PHP backdoors.
NEWS
Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin to inject malicious PHP code into WordPress installations. This campaign targets e-commerce sites, allowing attackers to upload backdoors and maintain persistent access.
Why I Care
This impacts all WordPress site owners using the specific WooCommerce plugin, risking data theft, defacement, and loss of customer trust. Successful exploitation grants attackers complete administrative control over the website and potentially the underlying server.
Next Steps
Site administrators using the affected plugin must update to the patched version immediately. If patching is not possible, disable the plugin and scan for existing PHP backdoors within 24 hours.
Source: BleepingComputer ·