ZeroHour

Search: “woocommerce”

27 stories

[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

An unauthenticated arbitrary file upload exploit was released for a WooCommerce component version 1.5.0, risking site compromise.

Exploit-DB published exploit #52642 targeting WooCommerce 1.5.0. The flaw allows unauthenticated arbitrary file uploads, which can lead to remote code execution on affected web servers. The disclosure text does not report exploitation in the wild.

Exploit-DB · 29d agoExploit / PoC

Hackers expose donor data from Russian fundraisers for Ukrainians, political prisoners

Hackers breached the Stripe-WooCommerce integrations of Russian fundraisers Davayte and You Are Not Alone, exposing donor emails and partial card details.

Unknown hackers accessed the payment accounts of two Russian fundraising projects, Davayte and You Are Not Alone, in mid-August via a shared Stripe-WooCommerce integration used to run online auctions. Exposed data included donor email addresses and, in some cases, the last four digits of payment cards and issuing bank names; full card numbers, cardholder names, and donation details were not taken. Stripe blocked the unauthorized access before the entire donor email database could be downloaded and found no evidence of fraudulent transactions. Attribution remains unclear, with organizers unable to rule out Russian security services; both groups are designated 'undesirable' organizations in Russia, making donor identities sensitive, and a separate alleged leak of data from 669 Stripe merchants by a hacker named 'Satanic' has no confirmed connection.

The Record · 13d agoData breach