# Critical Vulnerability in WooCommerce Plugin Threatens WordPress Sites

*Published September 16, 2026*
*Source: [https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/](https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/)*

## Executive Summary

Hackers are exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin, putting WordPress sites at risk of PHP backdoor attacks. Site owners must act swiftly to mitigate potential damage and secure their platforms.

## Article

A significant security vulnerability has been discovered in the WooCommerce Wholesale Lead Capture plugin, a premium add-on for WordPress sites. This flaw is being actively exploited by hackers to upload PHP backdoors, potentially compromising affected websites. The plugin, widely used by businesses relying on WordPress for e-commerce, is now under scrutiny as cybercriminals take advantage of the vulnerability to gain unauthorized access. 

WordPress site owners utilizing this plugin are at risk, as attackers can exploit the flaw to execute remote code and gain control over the website. This breach could lead to data theft, site defacement, or further malicious activities. Security experts emphasize the importance of immediate action to mitigate the threat and prevent potential damage. 

The developers of the WooCommerce Wholesale Lead Capture plugin have been informed of the issue and are expected to release a patch promptly. In the meantime, WordPress administrators are urged to disable the plugin until the security patch is applied. Regular monitoring and auditing of WordPress site activities are recommended to identify any signs of compromise. By staying vigilant and responding quickly, site owners can protect their assets and maintain the integrity of their online presence.
