Hackers Target WordPress Sites via WooCommerce Plugin
Cybercriminals are actively exploiting a critical vulnerability in a popular WordPress plugin to upload PHP backdoors to target sites.

Cybersecurity researchers have detected a new wave of attacks targeting WordPress-powered websites through a widely used e-commerce plugin.
The threat actors are exploiting a critical security flaw in the premium WooCommerce Wholesale Lead Capture plugin. This vulnerability allows unauthenticated attackers to upload malicious PHP files directly to vulnerable servers.
Once the backdoor is successfully uploaded, attackers gain remote access to the compromised website, enabling them to execute further malicious activities and maintain persistent control.
Web administrators are strongly advised to immediately check their installations, apply available security patches, and update third-party plugins to protect against these ongoing exploitation attempts.
This incident serves as a crucial reminder for website owners and developers globally about the importance of proactive vulnerability management, especially when utilizing commercial e-commerce extensions.



