HomeRisk ManagementsPHP Webshell Campaign Targets WordPress via Critical WooCommerce Vulnerability

PHP Webshell Campaign Targets WordPress via Critical WooCommerce Vulnerability

Published on

spot_img

Severe Vulnerability in WooCommerce Plugin Exposed: PHP Webshells Target WordPress Sites

In a significant security threat that has resurfaced four months after a critical patch was released, attackers have been exploiting a serious flaw in a third-party WooCommerce plugin to upload PHP webshells to WordPress sites. This alarming development was reported by Wordfence in a technical write-up published on September 14. The company revealed that its firewall had successfully blocked over 100,000 attempts to exploit CVE-2026-27540, which pertains to the WooCommerce Wholesale Lead Capture plugin. Developed by Rymera Web Co, this premium plugin has approximately 6,000 active installations, heightening concerns about the widespread impact of this vulnerability.

The vulnerability was first disclosed and patched on February 20 with the release of version 2.0.3.2. However, the persistent exploitation of the flaw raises questions about the efficacy of the fix and the overall cybersecurity measures in place within the WordPress ecosystem. Wordfence assigned a Common Vulnerability Scoring System (CVSS) rating of 9.8 to this flaw, indicating its critical nature. In contrast, the CVE record issued by Patchstack marked it with a score of 9.0, which reflects differing assessments regarding the complexity of the attack. Wordfence’s analysis indicated that the compromise could occur via a simple, unauthenticated request, underscoring the vulnerability’s severe implications.

The Mechanics of the Attack

At the heart of this vulnerability lies the AJAX action known as wwlc_file_upload_handler, which is designed to facilitate uploads from the plugin’s wholesale registration form. Unfortunately, this action is accessible to unauthenticated visitors, which is a glaring oversight in security protocols. The issue arises from the way the plugin checks file extensions against a list of allowed types, which is directly read from the request rather than being validated through a secure server-side configuration. As a result, an unauthorized attacker can manipulate this list to include PHP files, effectively converting a standard file upload into a mechanism for remote code execution.

To exacerbate the situation, the code invokes WordPress’s upload function with type checking disabled, allowing the extension check to serve as the sole line of defense against malicious uploads. Wordfence’s findings indicate that attackers have been submitting carefully crafted requests that feature a forged settings parameter, often accompanied by a PHP file named shell.php. The exploitation leads to the installation of a webshell that provides details about the host and carries a browser-based upload form, allowing further malicious files to be written onto the compromised site.

The timeline of exploit attempts reveals that the heaviest activity occurred between June 4 and June 17, with additional attempts recorded on July 1 and August 30. It is critical to note that all versions of the plugin up to and including 2.0.3.1 remain vulnerable, as highlighted by researcher Teemu Saarentaus, who initially reported the flaw.

Recommended Actions for Site Owners

Given the considerable risks associated with this vulnerability, Wordfence has issued specific recommendations for WordPress site owners. First and foremost, they should update their WooCommerce Wholesale Lead Capture plugin to version 2.0.3.2 or later to mitigate the risk of exploitation. While a firewall rule exists to block known exploit attempts, it does not replace the urgent necessity of patching the plugin itself, as all earlier versions continue to pose a threat.

Furthermore, Wordfence has urged site owners to meticulously review their uploads directory for any unexpected or recently created PHP files. They should also scrutinize web server access logs for abnormal requests directed at admin-ajax.php containing the vulnerable action. Any unexpected findings should lead to swift action, including the removal of unknown files and administrator accounts, alongside a thorough site review for potential backdoors or other security breaches.

The cybersecurity landscape for WordPress continues to evolve, and while this vulnerability is alarming, it also serves as a crucial reminder for site owners about the importance of regular updates and proactive monitoring. Even in the absence of matching log entries, it is essential to approach the defenses of their sites with diligence and caution, as a lack of evidence does not guarantee safety. The ongoing breaches illustrate the need for heightened vigilance in maintaining website security, particularly as third-party plugins remain a common attack vector in the broader web ecosystem.

Source link

Latest articles

LinkedIn Advocates for Transparency in Federal Data Requests

Privacy Now a ‘Data Stewardship Obligation’ In the evolving landscape of data privacy, a compelling...

Five Eyes Express Optimism Regarding AI’s Impact on Cybersecurity

Five Eyes Express Optimism on AI's Impact on Cyber Balance In a significant discussion on...

Cybersecurity Innovation Highlights International Cyber Expo Awards Shortlist

International Cyber Expo Unveils Shortlist for 2026 Innovation Awards Highlighting Cybersecurity Technologies The International Cyber...

Oracle’s September Patches Put Fusion Middleware Under Pressure

Oracle Issues Critical Security Updates and Warnings for Organizations Using Older Software Versions In a...

More like this

LinkedIn Advocates for Transparency in Federal Data Requests

Privacy Now a ‘Data Stewardship Obligation’ In the evolving landscape of data privacy, a compelling...

Five Eyes Express Optimism Regarding AI’s Impact on Cybersecurity

Five Eyes Express Optimism on AI's Impact on Cyber Balance In a significant discussion on...

Cybersecurity Innovation Highlights International Cyber Expo Awards Shortlist

International Cyber Expo Unveils Shortlist for 2026 Innovation Awards Highlighting Cybersecurity Technologies The International Cyber...