Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin 

SecurityVendor

On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution.
The post Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin appeared first on Wordfence.WordfenceRead More