:

WORDPRESS SITES HIT BY WOOCOMMERCE PLUGIN EXPLOIT

SECURITY DESK1 MIN READ
WED, SEP 16, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Attackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin to deploy PHP backdoors on WordPress sites. The flaw allows unauthorized code execution on affected installations.

Security researchers have detected active exploitation of a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin. The flaw enables attackers to upload malicious PHP files directly to compromised WordPress installations, establishing persistent backdoor access. The vulnerability affects the premium plugin, which is designed to capture and manage wholesale customer leads in WooCommerce stores. Attackers are leveraging the flaw to inject code that grants them ongoing control over target sites. WordPress site administrators using the WooCommerce Wholesale Lead Capture plugin should immediately update to the patched version. Users should also audit their sites for unauthorized PHP files and suspicious activity in their upload directories. This incident underscores the security risks associated with third-party WordPress plugins. Site operators are advised to keep all plugins updated, remove unused plugins, and use security plugins to monitor for unauthorized file uploads.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Google released September 2026 security updates addressing 110 vulnerabilities in Pixel devices, including a zero-day flaw currently being exploited in targeted attacks.

3H AGOSecurity Desk

Apple has introduced Reference Image, a new approach to verified photography that authenticates images at the point of capture. The technology aims to combat image manipulation and provide proof of content authenticity.

3H AGOIndustry Desk

Cybersecurity professionals are pushing back against apocalyptic hacking predictions from AI industry leaders, calling the warnings technically incoherent and based on fundamental misunderstandings of cybersecurity.

7H AGOAI Desk

Security expert Bruce Schneier argues that two and a half decades of mass surveillance programs have failed to deliver promised security benefits and should be dismantled. The call comes as surveillance capabilities continue expanding globally.

7H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.