ZeroHour
Wordfencepublished ()ingested István Márton1

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

highExploit / PoC exploited in the wildimportance 65
AI summary · glm-5.3

Attackers are actively exploiting an unauthenticated arbitrary file upload flaw in the WooCommerce Wholesale Lead Capture plugin, enabling PHP backdoors and remote code execution.

A critical unauthenticated arbitrary file upload vulnerability in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations, was publicly disclosed on February 20, 2026. Wordfence reports attackers are now actively exploiting the flaw to upload arbitrary files, including PHP backdoors, and achieve remote code execution. No CVE ID was cited in the report.

  • Unauthenticated arbitrary file upload enables PHP backdoor upload and RCE
  • Premium WordPress plugin with roughly 6,000 active installations
  • Vulnerability publicly disclosed February 20, 2026
  • Active exploitation observed in the wild
Full article

On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The post Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin appeared first on Wordfence.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.