TechRadar News.
Technology

Hackers Abuse WooCommerce Wholesale Lead Capture Plugin to Install PHP Backdoors

Hackers Abuse WooCommerce Wholesale Lead Capture Plugin to Install PHP Backdoors

Researchers in cybersecurity have confirmed that attackers are exploiting a serious vulnerability in the premium WooCommerce Wholesale Lead Capture plugin for WordPress, allowing them to place a malicious PHP backdoor on compromised sites.

The flaw resides in the plugin’s lead‑capture function, which does not correctly validate uploaded files. When maliciously crafted requests are sent, the backdoor script can be deposited on the server without any authentication, giving the intruder the power to run arbitrary commands and retain ongoing access.

Approximately 40% of all websites run on WordPress, and its plugin‑based flexibility turns it into a common exploitation target. WooCommerce, the top e‑commerce add‑on for the platform, offers thousands of extensions, among them the Wholesale Lead Capture utility that merchants employ to gather data from bulk‑buyer leads. Since this extension is marketed as a premium product, many administrators presume it receives prompt security updates, a belief that can obscure the underlying danger.

Once the backdoor is in place, threat actors can move laterally to exfiltrate credentials, alter website content, or initiate additional assaults on visitors. The intrusion may also enable ransomware deployment or site defacement, extending the damage far beyond the original breach. Analysts caution that detecting such a backdoor is challenging without comprehensive file‑system examinations, since the malicious code can masquerade as a legitimate part of the plugin.

The plugin’s developers have reacted by issuing an urgent update that fixes the file‑validation flaw. They advise every user of the Wholesale Lead Capture add‑on to install the patch without delay and to audit server logs for any anomalous upload behavior. Concurrently, WordPress security specialists suggest tightening site settings—for example, turning off direct PHP execution in upload folders and deploying web‑application firewalls.

This episode highlights the wider difficulty of safeguarding third‑party extensions within the WordPress ecosystem. With the platform maintaining its dominance in web publishing, developers and site operators alike need to implement proactive strategies—frequent updates, continuous vulnerability monitoring, and thorough testing—to reduce the likelihood of comparable exploits moving forward.

TechRadar Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related