Critical WooCommerce Plugin Flaw Enables PHP Backdoor Infections Across WordPress Sites
Security researchers have confirmed that a critical vulnerability in a premium WooCommerce add‑on is being actively exploited to install malicious PHP backdoors on WordPress sites, giving attackers unrestricted code execution capabilities.
The affected component, WooCommerce Wholesale Lead Capture, is a paid plugin that lets online merchants gather wholesale inquiries directly from their storefronts. The flaw stems from inadequate validation of files uploaded through the plugin’s lead‑capture form, allowing specially crafted requests to place executable code on the server.
Exploitation follows a straightforward pattern: an attacker submits a request to the vulnerable endpoint, bypasses the plugin’s file‑type checks, and uploads a PHP script disguised as a legitimate file. Once the script resides on the host, it can be invoked remotely, enabling the attacker to run commands, alter site content, or move laterally within the compromised network.
Because WooCommerce powers a significant portion of e‑commerce sites worldwide, any installation that employs the Wholesale Lead Capture extension is potentially at risk. Early indicators show that several websites have already been compromised since the vulnerability’s public disclosure, and automated scanning tools are likely probing the internet for vulnerable instances.
The plugin’s developer responded by releasing an emergency patch that tightens file‑upload handling and adds stricter MIME‑type verification. In parallel, the WordPress security team issued an advisory urging site owners to apply the update without delay, deactivate the plugin if it is not essential, and conduct thorough scans for lingering backdoors.
Experts recommend a layered defence approach: keep WordPress core, themes, and all plugins current; employ reputable security plugins that monitor file integrity; restrict file‑system permissions to the minimum required; and regularly review server logs for anomalous activity. Continuous vigilance will be necessary as threat actors may shift focus to other vulnerable extensions if this avenue is closed.
Comments (0)
Be the first to comment.
Join the discussion