$ techbeacon▋
CVE & Exploits

Critical WooCommerce Plugin Flaw Enables PHP Backdoor Infections Across WordPress Sites

Critical WooCommerce Plugin Flaw Enables PHP Backdoor Infections Across WordPress Sites

Security researchers have confirmed that a critical vulnerability in a premium WooCommerce add‑on is being actively exploited to install malicious PHP backdoors on WordPress sites, giving attackers unrestricted code execution capabilities.

The affected component, WooCommerce Wholesale Lead Capture, is a paid plugin that lets online merchants gather wholesale inquiries directly from their storefronts. The flaw stems from inadequate validation of files uploaded through the plugin’s lead‑capture form, allowing specially crafted requests to place executable code on the server.

Exploitation follows a straightforward pattern: an attacker submits a request to the vulnerable endpoint, bypasses the plugin’s file‑type checks, and uploads a PHP script disguised as a legitimate file. Once the script resides on the host, it can be invoked remotely, enabling the attacker to run commands, alter site content, or move laterally within the compromised network.

Because WooCommerce powers a significant portion of e‑commerce sites worldwide, any installation that employs the Wholesale Lead Capture extension is potentially at risk. Early indicators show that several websites have already been compromised since the vulnerability’s public disclosure, and automated scanning tools are likely probing the internet for vulnerable instances.

The plugin’s developer responded by releasing an emergency patch that tightens file‑upload handling and adds stricter MIME‑type verification. In parallel, the WordPress security team issued an advisory urging site owners to apply the update without delay, deactivate the plugin if it is not essential, and conduct thorough scans for lingering backdoors.

Experts recommend a layered defence approach: keep WordPress core, themes, and all plugins current; employ reputable security plugins that monitor file integrity; restrict file‑system permissions to the minimum required; and regularly review server logs for anomalous activity. Continuous vigilance will be necessary as threat actors may shift focus to other vulnerable extensions if this avenue is closed.

Mahesh Kumar Sahoo — Mahesh covers ransomware gangs, data leak sites, and dark web marketplaces, mapping how stolen data surfaces and gets sold. Follows ShinyHunters-style groups across leak forums.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related