Technologies
Back
Cybersecurity & Privacy

Critical WooCommerce Plugin Vulnerability Leads to PHP Backdoor Attacks

TechRadar
Advertisement468 × 90
Critical WooCommerce Plugin Vulnerability Leads to PHP Backdoor Attacks

Security researchers at Defiant have reported active exploitation of a critical unauthenticated file-upload vulnerability (CVE-2026-27540) in the Wholesale Lead Capture Plugin for WooCommerce. The flaw, which carries a severity score of 9.0, allows attackers to upload PHP webshells, potentially granting them full control over affected WordPress websites. Although a patch (version 2.0.3.2) was released in February 2026, the Wordfence firewall has blocked over 100,000 attack attempts, with significant spikes in activity observed throughout the summer. Attackers are primarily using these webshells to map site infrastructure and deploy further malicious payloads. With over 20,000 active installations, experts are urging administrators to update the plugin immediately and conduct thorough audits of their upload directories for unauthorized PHP files. This incident highlights the ongoing risks associated with unpatched third-party plugins in the WordPress ecosystem.

This is a summary. Read the full article at the original source:

TechRadar
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250