Skip to main content
CyberSingle-sourceMediumDeveloping
5.2

Critical WooCommerce plugin flaw exploited to upload PHP backdoors

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin to upload PHP backdoors on WordPress sites. The attack is ongoing and affects sites using the plugin, with potential for full site compromise. This highlights the risk of third-party plugin supply chain vulnerabilities.

BleepingComputerabout 17 hours agoengCredibility 32%View source

Score Breakdown

Mosaic Score5.2
Confidence0.7
Significance0.5
Source credibility0.3
Source

Related signals

8 found