CYBERSECURITYTRACKER
TRACKING6,877 stories in this site build1,441 vulnerability news stories in this site build
Permanent story citation

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7456

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Unauthenticated attackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin to upload PHP web shells and gain remote code execution. Wordfence reports blocking multiple attack attempts against the plugin, which has over 6,000 active installations.

Why it matters: WordPress site operators using this plugin face immediate compromise risk; patch or disable the plugin now to prevent unauthorized access and data theft.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary