← Back to Feed
Hackers target WordPress sites via third-party WooCommerce plugin
September 15, 2026 · BleepingComputer · Severity: CRITICAL
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.
Key Takeaways
- Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP backdoors.
- The plugin vulnerability allows attackers to gain remote code execution on vulnerable WordPress sites running the premium extension.
- WordPress site owners using WooCommerce should immediately update or disable the Wholesale Lead Capture plugin to prevent compromise.