15-09-2026
Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/
Report completeness: Low
Victims:
Woocommerce wholesale lead capture, Wordpress websites
ChatGPT TTPs:
do not use without manual checkT1105, T1190, T1505.003
IOCs:
File: 1
IP: 9
Soft:
WordPress
Functions:
wwlc_file_upload_handler, get_allowed_mime_types, time
Languages:
php
Platforms:
x64