CuraSec

Act active

Hackers Exploit WooCommerce Wholesale Lead Capture Plugin for PHP Backdoor

2026-09-15 15:32 UTC · BleepingComputer · read the source ↗ #wordpress#active-exploitation#web-shell
  • Engineer — Act: Active exploitation of a critical file-upload flaw is in progress; if you run WooCommerce Wholesale Lead Capture, update or disable it immediately and audit wp-content for recently created PHP files that could be backdoors.
  • SOC/IR — Act: PHP backdoor upload attacks against WordPress sites are active; hunt for anomalous PHP files in wp-content/uploads and similar directories, and review web logs for suspicious POST requests to this plugin’s endpoints since the campaign began.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.