Close Menu
NCIJ Network NCIJ Network
    What's Hot

    AI on course to kill us all within 10 years? Donald Trump says: ‘Hold my Coke’ | John Crace

    September 15, 2026

    Ministers could force phone companies to add ‘anti-theft protections’

    September 15, 2026

    This doorbell camera lets a human security guard watch your front door

    September 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI on course to kill us all within 10 years? Donald Trump says: ‘Hold my Coke’ | John Crace
    • Ministers could force phone companies to add ‘anti-theft protections’
    • This doorbell camera lets a human security guard watch your front door
    • Hackers target WordPress sites via third-party WooCommerce plugin
    • Stablecoins Could Strengthen US Dollar, BoE Official Says
    • Celebrate International Observe the Moon Night with NASA
    • Thumbs-up for Equinor’s North Sea drilling ops with COSL rig
    • Guest opinion: Wisconsin has tried to improve reading for decades. Will this time be different?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 15
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers target WordPress sites via third-party WooCommerce plugin

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 15, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.

    The flaw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vulnerability discovered by security researcher Teemu Saarentaus.

    An attacker can exploit it to upload PHP webshells and execute code, potentially leading to a complete site compromise.

    From a technical standpoint, the flaw is caused by exposing  an unauthenticated AJAX action named wwlc_file_upload_handler, which checks file extensions against an allowlist supplied through the user-controlled file_settings request parameter.

    This allows adding ‘php’ to the permitted file types, making the plugin accept PHP executable file uploads.

    The vulnerability was addressed in version 2.0.3.2 of the WooCommerce Wholesale Lead Capture plugin, released on February 20.

    However, WordPress security company Defiant is warning that its Wordfence web application firewall blocked over 100,000 attacks linked to CVE-2026-27540.

    Wordfence reports that exploitation activity spiked between June 4 and June 17, and on July 1 and August 30.

    During the attacks, the hackers upload a webshell that conducts reconnaissance but can also introduce additional payloads.

    “The attacker submits a request to the wwlc_file_upload_handler AJAX action containing a forged file_settings parameter and a malicious file with a .php extension,” Wordfence explains.

    “The uploaded shell.php is a PHP webshell that reports host details and provides a browser-based upload form for writing additional malicious files to the site.”

    Attack request
    Example attack request
    Source: Wordfence

    Wordfence provides a set of high-offender IP addresses that deployed tens of thousands of exploitation attempts. Administrators are recommended to add them to a blocklist and upgrade to plugin version 2.0.3.2 or later that addresses the security problem.

    The researchers advise checking upload directories for unexpected or recently created PHP files, examining logs for requests to /wp-admin/admin-ajax.php invoking wwlc_file_upload_handler, and removing unknown administrator accounts.

    If compromise is confirmed, the recommended action is to restore the website from a safe backup, as removing all persistence mechanisms, users, and backdoors may be complicated.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    hackers Plugin sites Target thirdparty WooCommerce WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    CenterPoint Energy confirms customer data stolen in cyberattack

    BambooToken Malware Uses MQTT to Control Windows and Linux Systems

    BambooToken malware controls Windows and Linux systems via MQTT

    Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

    Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

    240,000 Hit by Data Breach at Japan’s Digital Agency

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    AI on course to kill us all within 10 years? Donald Trump says: ‘Hold my Coke’ | John Crace

    September 15, 2026

    Ministers could force phone companies to add ‘anti-theft protections’

    September 15, 2026

    This doorbell camera lets a human security guard watch your front door

    September 15, 2026

    Hackers target WordPress sites via third-party WooCommerce plugin

    September 15, 2026
    Latest Posts

    Two new compounds could reveal hidden drivers of Alzheimer’s disease

    August 4, 2026

    Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    AI on course to kill us all within 10 years? Donald Trump says: ‘Hold my Coke’ | John Crace

    September 15, 2026

    Ministers could force phone companies to add ‘anti-theft protections’

    September 15, 2026

    This doorbell camera lets a human security guard watch your front door

    September 15, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.