A Critical Vulnerability in WooCommerce Wholesale Exposes Thousands of Websites to Attackers
A severe security flaw has been discovered in the popular e-commerce plugin WooCommerce Wholesale, leaving thousands of websites vulnerable to attacks. Hackers have already begun exploiting this weakness, planting malicious PHP web shells on compromised sites that can be used for further exploitation. The vulnerability, which affects versions 4.9.x and earlier of the plugin, allows attackers to inject malicious code into a website’s database, potentially leading to a range of devastating consequences.
The WooCommerce Wholesale plugin is widely used by online merchants to manage wholesale pricing and inventory levels. However, in this instance, its functionality has been hijacked by cybercriminals who have identified a weakness that can be exploited for unauthorized access. By injecting malicious code into the website’s database, attackers can gain control over sensitive data, inject malware, or even use the compromised site as a launchpad for further attacks on other sites.
The exploit works by targeting a flaw in the plugin’s lead capture functionality, which is designed to collect customer information from wholesale customers. However, this feature has been subverted by hackers who are using it to plant PHP web shells on vulnerable websites. These web shells can be used to execute malicious code, potentially leading to data breaches, site defacement, or even a full-scale takeover of the compromised site.
The implications of this vulnerability are significant, and online merchants should take immediate action to protect themselves. With thousands of websites affected, the potential for widespread damage is high. Moreover, the fact that hackers have already begun exploiting this weakness suggests that the threat landscape has become increasingly complex, with cybercriminals adapting their tactics to target even the most secure-looking sites.
As a result, website owners and administrators should review their plugin configurations and update WooCommerce Wholesale to the latest version (4.10.x) as soon as possible. Additionally, conducting regular security audits and implementing robust monitoring tools can help detect potential breaches before they escalate into full-scale attacks. By taking proactive measures to address this vulnerability, online merchants can minimize the risk of falling victim to these types of attacks.
Source: The Hacker News — 2026-09-16