← Back to Feed

Hackers target WordPress sites via third-party WooCommerce plugin

September 15, 2026 · BleepingComputer · Severity: CRITICAL

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.

Key Takeaways

  • Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP backdoors.
  • The plugin vulnerability allows attackers to gain remote code execution on vulnerable WordPress sites running the premium extension.
  • WordPress site owners using WooCommerce should immediately update or disable the Wholesale Lead Capture plugin to prevent compromise.
☕ Buy a Coffee