Hackers are exploiting a critical vulnerability in a premium WooCommerce plugin to upload malicious server-side code to WordPress sites. Reporting from multiple outlets says the flaw enables unauthenticated attackers to upload arbitrary files, including PHP backdoors, which can lead to remote code execution.
The affected plugin is the “WooCommerce Wholesale Lead Capture” premium extension. One report says the plugin has more than 6,000 active installs. Security researchers also describe the activity as resulting in the placement of PHP web shells on compromised sites. The outlets attribute details of the exploitation method to security firm analysis and note that defenses have been put in place to block the attacks.
While the accounts align on the core mechanism—unauthenticated file upload leading to PHP backdoors—outlets emphasize different framing. One focuses on the upload of a PHP backdoor, while another specifically describes the planting of PHP web shells. Both portray the campaign as active rather than historical.