Hackers target WordPress sites via third-party WooCommerce plugin
Summary
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress. This exploit allows them to upload a PHP backdoor onto compromised websites.
IFF Assessment
The article details an active exploit of a critical vulnerability, which represents a direct threat to website security and data.
Severity
The vulnerability allows for unauthenticated remote code execution and arbitrary file upload, leading to a complete site takeover. Given its critical nature and the ease of exploitation, a high CVSS score is appropriate.
Defender Context
This highlights the importance of maintaining up-to-date plugins, especially for e-commerce platforms like WordPress. Defenders should prioritize patching or disabling vulnerable plugins immediately and monitor for any signs of backdoor installations.