Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.

“This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution,” Wordfence said.

The WordPress security company said it has blocked over

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

AI 2040 and the Cult of Intelligence

AI 2040 and the Cult of Intelligence Source: Hacker News

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government

Hacking with Claude on a $27 Smart Watch

Hacking with Claude on a $27 Smart Watch Source: Hacker News