Critical WooCommerce Plugin Vulnerability Leads to PHP Backdoor Attacks

Security researchers at Defiant have reported active exploitation of a critical unauthenticated file-upload vulnerability (CVE-2026-27540) in the Wholesale Lead Capture Plugin for WooCommerce. The flaw, which carries a severity score of 9.0, allows attackers to upload PHP webshells, potentially granting them full control over affected WordPress websites. Although a patch (version 2.0.3.2) was released in February 2026, the Wordfence firewall has blocked over 100,000 attack attempts, with significant spikes in activity observed throughout the summer. Attackers are primarily using these webshells to map site infrastructure and deploy further malicious payloads. With over 20,000 active installations, experts are urging administrators to update the plugin immediately and conduct thorough audits of their upload directories for unauthorized PHP files. This incident highlights the ongoing risks associated with unpatched third-party plugins in the WordPress ecosystem.
This is a summary. Read the full article at the original source:
TechRadarRelated stories
Apple has introduced a new open-source project called 'Apple Reference Image' aimed at enhancing the authenticity of digital photography. As deepfakes…
A suspected North Korean advanced persistent threat (APT) group has launched a targeted cyber campaign against South Korean media and automotive organ…
GhostShield VPN introduces AI-powered threat detection in lifetime subscription offer
GhostShield has launched a new VPN service that integrates artificial intelligence to enhance traditional online privacy. Unlike standard VPNs that fo…



