Tech News
← Home  ·  All topics

Webshell

2 GoKawiil briefs on this topic

WooCommerce Wholesale Lead Capture flaw exploited to plant PHP backdoors

Hackers are exploiting an unauthenticated file-upload vulnerability (CVE-2026-27540) in the WooCommerce Wholesale Lead Capture plugin for WordPress, versions 2.0.3.1 and earlier, to install PHP webshells. Wordfence says its firewall has blocked over 100,000 attack attempts, with spikes in June, July and August, and the shells allow attackers to gather site information and upload further malicious files.

Attackers exploit patched Elementor Pro flaw to plant webshells on WordPress sites

Hackers are actively exploiting CVE-2026-32475, a critical vulnerability in Elementor Pro affecting version 4.2.1 and earlier, by abusing a file-upload validation flaw in the plugin's form widget to upload malicious PHP files and run commands on compromised servers. Elementor patched the bug on August 19 with version 4.2.2, but Wordfence says exploitation began the same day and has already blocked nearly 200,000 attack attempts.