VulnerabilitiesWordPress plugin flaw is being used to plant hidden backdoors on shop sites
A file-upload bug in WooCommerce Wholesale Lead Capture lets attackers drop PHP webshells with no login required. Wordfence has blocked more than 100,000 attempts.