Skip to main content

Tag: php webshells

2 articles

Retail store checkout counter with POS terminal, shopping items, and mobile devices.

WooCommerce Plugin Flaw Exploited to Upload PHP Webshells on WordPress Sites

Hackers have been actively exploiting a critical flaw in the WooCommerce Wholesale Lead Capture plugin to upload malicious PHP webshells to WordPress sites, despite a patch being available since February. Over 100,000 exploitation attempts were blocked by Wordfence's firewall, with multiple waves of attacks occurring over several months.

Analyst 207
WordPress website backend interface on a laptop screen with a cityscape background.

WordPress Sites Targeted as Hackers Exploit Critical wp2shell Flaws

Hackers are actively exploiting critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to inject malicious plugins and PHP webshells, putting countless sites at risk. Attackers are using mass-scanning and plugin upload abuse to gain control, making it essential for WordPress users to take immediate action.

Analyst 207