Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Summary

Attackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin, which has over 6,000 active installations. This flaw allows unauthenticated attackers to upload arbitrary files, including PHP backdoors, leading to remote code execution.

IFF Assessment

FOE

The article details a vulnerability that allows attackers to gain remote code execution on compromised systems, posing a direct threat to defenders.

Severity

9.8 Critical (AI Estimated)

The vulnerability allows for arbitrary file upload leading to remote code execution by unauthenticated attackers, indicating a critical severity with high exploitability and impact.

Defender Context

Defenders should prioritize patching or disabling the WooCommerce Wholesale Lead Capture plugin if used, as it is being actively exploited for remote code execution. This incident highlights the ongoing risk posed by vulnerable third-party plugins in WordPress environments.

Read Full Story →