As cited
Copy frozen at (site build).
vulnerabilities
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Unauthenticated attackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin to upload PHP web shells and gain remote code execution. Wordfence reports blocking multiple attack attempts against the plugin, which has over 6,000 active installations.
Why it matters: WordPress site operators using this plugin face immediate compromise risk; patch or disable the plugin now to prevent unauthorized access and data theft.
- Source published
- First seen by Cybersecurity Tracker