Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

September 16, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: WordPress website administrators
Incident: Active exploitation of critical RCE vulnerabilities in several popular WordPress plugins.
Impact: Complete server compromise, unauthorized file uploads, and full website takeover.
Attacker: Unidentified threat actors
Analysis: Attackers are exploiting missing file validation in the WooCommerce Wholesale Lead Capture plugin to upload PHP web shells for remote code execution. Simultaneously, flaws in The Events Calendar plugin allow unauthenticated users to achieve full site takeover via the widget-rendering pipeline. These campaigns target wide user bases, utilizing common AJAX handlers and comment previews to bypass security.
Recommendations: Update WooCommerce Wholesale Lead Capture and The Events Calendar plugins to the latest versions immediately.; Audit the uploads directory for unauthorized .php files or web shells.; Monitor web server logs for suspicious requests to admin-ajax.php containing wwlc_file_upload_handler.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *