← Back to blog

WooCommerce Plugin Flaw Lets Attackers Deploy PHP Web Shells

A critical vulnerability in WooCommerce Wholesale Lead Capture is being exploited to upload PHP backdoors. Unauthenticated attackers can achieve remote code execution on affected sites.

TL;DR

  • Attackers are exploiting a critical flaw in WooCommerce Wholesale Lead Capture plugin.
  • The vulnerability allows unauthenticated file uploads, including PHP web shells.
  • Over 6,000 active WordPress installations are potentially at risk.
  • Wordfence has already blocked thousands of exploit attempts.
  • Site owners should update or disable the plugin immediately.

Threat actors are actively exploiting a severe security vulnerability in the WooCommerce Wholesale Lead Capture plugin, which is installed on over 6,000 WordPress sites. The flaw enables unauthenticated attackers to upload malicious files, including PHP web shells, leading to remote code execution.

According to Wordfence, a leading WordPress security firm, the vulnerability is under active exploitation. They report having already blocked thousands of attack attempts, underscoring the urgency for site administrators to take protective action.

Vulnerability Details

  • The flaw affects WooCommerce Wholesale Lead Capture, a premium plugin with over 6,000 active installs.
  • It allows unauthenticated users to upload arbitrary files, including PHP backdoors.
  • Successful exploitation grants attackers remote code execution capabilities.
  • No authentication is required to trigger the vulnerability, increasing its severity.

Impact and Response

  • Wordfence has detected and blocked over 4,500 exploit attempts in the wild.
  • Affected sites risk full compromise, including data theft and persistent backdoor access.
  • WordPress site owners should immediately disable or remove the plugin if not in use.
  • Updating to the latest patched version is strongly recommended for continued use.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

WooCommerce Plugin Flaw Lets Attackers Deploy PHP Web Shells — Agent Breach Blog | Agent Breach