ZeroHour

Search: “WooCommerce”

5 stories in the last 30d

CVE-2026-27540 WooCommerce Flaw Exploited

Attackers are actively exploiting CVE-2026-27540, a critical arbitrary file-upload flaw in the WooCommerce Wholesale Lead Capture WordPress plugin.

Attackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture plugin for WordPress. The critical arbitrary file-upload vulnerability lets attackers place malicious files on vulnerable sites, typically enabling webshell deployment or code execution. WordPress sites running the plugin should update immediately.

SOCRadarupdated · 9h agofirst · 12h agoExploit / PoC in the wild 6 sourcesCVE-2026-27540

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

Attackers are actively exploiting an unauthenticated arbitrary file upload flaw in the WooCommerce Wholesale Lead Capture plugin, enabling PHP backdoors and remote code execution.

A critical unauthenticated arbitrary file upload vulnerability in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations, was publicly disclosed on February 20, 2026. Wordfence reports attackers are now actively exploiting the flaw to upload arbitrary files, including PHP backdoors, and achieve remote code execution. No CVE ID was cited in the report.

Wordfence · 2d agoExploit / PoC in the wild1

Hackers expose donor data from Russian fundraisers for Ukrainians, political prisoners

Hackers breached the Stripe-WooCommerce integrations of Russian fundraisers Davayte and You Are Not Alone, exposing donor emails and partial card details.

Unknown hackers accessed the payment accounts of two Russian fundraising projects, Davayte and You Are Not Alone, in mid-August via a shared Stripe-WooCommerce integration used to run online auctions. Exposed data included donor email addresses and, in some cases, the last four digits of payment cards and issuing bank names; full card numbers, cardholder names, and donation details were not taken. Stripe blocked the unauthorized access before the entire donor email database could be downloaded and found no evidence of fraudulent transactions. Attribution remains unclear, with organizers unable to rule out Russian security services; both groups are designated 'undesirable' organizations in Russia, making donor identities sensitive, and a separate alleged leak of data from 669 Stripe merchants by a hacker named 'Satanic' has no confirmed connection.

The Record · 14d agoData breach

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress will automatically scan every plugin release and block high-risk updates from distribution using AI analysis plus Jetpack Scan.

WordPress announced automated security reviews for every plugin release during its cooldown period before distribution through the WordPress.org update API, combining AI models with Jetpack Scan into a security score. The system already caught a backdoor committed to a plugin with about 20,000 active installations on July 28, 2026, blocking it within 26 minutes of a Wordfence alert. Flagged patterns include missing capability checks, unsafe $wpdb queries, unserialize() on request data, and obfuscated code.

The Hacker News · 2d agoTools

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 12d agoPolicy & legal