Security
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News·September 16, 2026·1 min read
Threat actors are exploiting a critical flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with over 6,000 active installs. Wordfence said unauthenticated attackers can upload arbitrary files, including PHP backdoors, achieving remote code execution. The security firm has blocked over 100 attacks so far.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
