thehackernews.com 16 Sept 2026, 05:48 UTC

WooCommerce Plugin Flaw Lets Attackers Plant Web Shells

WooCommerce Plugin Flaw Lets Attackers Plant Web Shells
CyberSIXT Evidence Panel Source marked as original reporting

ATTACKERS are exploiting a vulnerability in the WooCommerce Wholesale Lead Capture plugin, allowing them to plant PHP web shells on affected sites. This compromise can lead to severe security risks, including unauthorized access and control over the web server. Users are advised to update their plugins and implement security measures to mitigate the risk of these attacks.

View full article

Article by CyberSIXT