chiprook
← Security
SecuritySeptember 15, 2026, 21:45

Hackers target WordPress sites via third-party WooCommerce plugin

A critical vulnerability CVE-2026-27540 in the premium WooCommerce Wholesale Lead Capture plugin (versions 2.0.3.1 and older) allows unauthenticated PHP backdoor uploads. Wordfence blocked over 100,000 attacks; a fix was released in version 2.0.3.2 on 20 February.

Hackers target WordPress sites via third-party WooCommerce plugin
#WordPress#WooCommerce#Wordfence
Read next
Security

WordPress Click2Shell flaw lets hackers run PHP on the server

Security

ZoomEye: Over 239,000 Citrix NetScaler Gateways Exposed Amid SAML Bypass

Security

Microsoft and Google take down $66 million RedVDS cybercrime marketplace

Security

Contagious Interview Campaign Hits 30,000 Devices, Steals $10.71M in Crypto