Summary Points
- Attackers are exploiting a vulnerability in WooCommerce Wholesale Lead Capture (CVSS 9.8) to upload malicious PHP files and execute remote code, with over 100,000 attempts since June 2026.
- Critical flaws in The Events Calendar (CVSS 9.8) enable unauthenticated remote code execution via widget-rendering vulnerabilities, risking full site takeover and data theft.
- Both vulnerabilities can be triggered through common WordPress features like AJAX uploads and comment previews, emphasizing the need for immediate patching and monitoring for suspicious activity.
Threat, Attack Techniques, and Targets
Threat actors are exploiting a severe security issue in the WooCommerce Wholesale Lead Capture plugin, which is common on WordPress sites. They are using a flaw that allows unauthenticated users to upload any files they want. This is possible because the plugin does not properly check the types of files being uploaded. The attackers send specially crafted requests to the “wwlc_file_upload_handler” AJAX action, including a malicious PHP file like “shell.php.” This PHP file acts as a web shell, giving attackers control over the website. Since more than 6,000 sites use this plugin, many are at risk. The attack targets the WordPress sites running the vulnerable plugin.
Impact, Security Implications, and Remediation Guidance
Because the flaw allows attackers to upload PHP backdoors, they can run malicious code on the website. This can lead to remote code execution, meaning attackers can control the website completely. They can also use the web shell to write more malicious files and steal sensitive data. This vulnerability increases the risk of malware infections and site takeovers. To reduce this risk, site owners should look for suspicious PHP files, especially in upload folders. Also, review logs for unusual requests to “admin-ajax.php” from known malicious IP addresses. Since a fix has been released, it is vital to update the plugin to the latest versions provided by the developer. For detailed remediation guidance, it is recommended to contact the plugin vendor or consult official security resources.
Discover More Technology Insights
Learn how the Internet of Things (IoT) is transforming everyday life.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
