Tag: php webshells
2 articles

WooCommerce Plugin Flaw Exploited to Upload PHP Webshells on WordPress Sites
Hackers have been actively exploiting a critical flaw in the WooCommerce Wholesale Lead Capture plugin to upload malicious PHP webshells to WordPress sites, despite a patch being available since February. Over 100,000 exploitation attempts were blocked by Wordfence's firewall, with multiple waves of attacks occurring over several months.

WordPress Sites Targeted as Hackers Exploit Critical wp2shell Flaws
Hackers are actively exploiting critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to inject malicious plugins and PHP webshells, putting countless sites at risk. Attackers are using mass-scanning and plugin upload abuse to gain control, making it essential for WordPress users to take immediate action.