Hackers target WordPress sites via third-party WooCommerce plugin

Summary

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress. This exploit allows them to upload a PHP backdoor onto compromised websites.

IFF Assessment

FOE

The article details an active exploit of a critical vulnerability, which represents a direct threat to website security and data.

Severity

9.8 Critical (AI Estimated)

The vulnerability allows for unauthenticated remote code execution and arbitrary file upload, leading to a complete site takeover. Given its critical nature and the ease of exploitation, a high CVSS score is appropriate.

Defender Context

This highlights the importance of maintaining up-to-date plugins, especially for e-commerce platforms like WordPress. Defenders should prioritize patching or disabling vulnerable plugins immediately and monitor for any signs of backdoor installations.

Read Full Story →