Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Cyberattackers have been exploiting a critical vulnerability in WooCommerce’s Wholesale Lead Capture plugin, allowing them to plant malicious PHP web shells on compromised websites. This security flaw, which affects thousands of online stores using the plugin, has been actively exploited by attackers to gain unauthorized access and potentially steal sensitive data.

The vulnerability, discovered earlier this year, enables attackers to inject arbitrary code into the vulnerable plugin’s files, effectively creating a backdoor that can be used to plant web shells. Web shells are malicious scripts that allow attackers to remotely execute commands on a compromised server, giving them complete control over the affected website and its underlying infrastructure.

The Wholesale Lead Capture plugin is widely used by online merchants to manage sales leads and customer interactions. However, its popularity has also made it a prime target for attackers seeking to exploit vulnerabilities in popular plugins. According to WooCommerce’s own estimates, over 1 million websites use their plugins, with the Wholesale Lead Capture plugin alone installed on around 100,000 sites.

Attackers have been exploiting this vulnerability by injecting malicious code into the plugin’s files, which are then executed when a user interacts with the affected website. This allows them to plant web shells that can be used to steal sensitive data, inject malware, or even hold websites for ransom. The exploitation of this vulnerability has also raised concerns about the potential for cross-domain privilege escalation, where attackers could use compromised websites as launchpads to breach other sites within the same network.

The severity of this vulnerability is further compounded by its ease of exploitation. Attackers can exploit the flaw simply by visiting a vulnerable website and interacting with it in some way. This means that users are at risk even if they don’t click on any links or download any attachments – simply browsing to an affected site can be enough for the attack to succeed.

As online merchants continue to rely on third-party plugins to manage their websites, this vulnerability serves as a stark reminder of the importance of keeping software up-to-date and implementing robust security measures. Website owners are advised to update their Wholesale Lead Capture plugin to the latest version available and to conduct regular security audits to identify potential vulnerabilities before they can be exploited.

In light of this incident, website owners would do well to review their security protocols and ensure that they have adequate controls in place to prevent similar attacks from succeeding. This includes keeping all software up-to-date, implementing robust access controls, and regularly monitoring for suspicious activity on their websites. By taking these precautions, online merchants can reduce the risk of falling victim to similar attacks in the future.


Source: The Hacker News — 2026-09-16