Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Summary
Attackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin, which has over 6,000 active installations. This flaw allows unauthenticated attackers to upload arbitrary files, including PHP backdoors, leading to remote code execution.
IFF Assessment
The article details a vulnerability that allows attackers to gain remote code execution on compromised systems, posing a direct threat to defenders.
Severity
The vulnerability allows for arbitrary file upload leading to remote code execution by unauthenticated attackers, indicating a critical severity with high exploitability and impact.
Defender Context
Defenders should prioritize patching or disabling the WooCommerce Wholesale Lead Capture plugin if used, as it is being actively exploited for remote code execution. This incident highlights the ongoing risk posed by vulnerable third-party plugins in WordPress environments.