BreachFeed

Shared from BreachFeed

The Hacker News·

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

Read the full article at thehackernews.com

Hear about the next one the moment it breaks

BreachFeed watches security news, breach disclosures and government advisories around the clock and alerts you by email, text or push when the organizations and keywords you track come up.

Create a free accountBrowse the latest news
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu3q8to97jruhpu2ut9k836o