Economy
Critical Woocommerce Plugin Flaw Exploited by Threat Actors

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with more than 1,000 active installations. The vulnerability, tracked as CVE-2025-4435, carries a CVSS score of 9.8 out of 10 and allows unauthenticated attackers to upload arbitrary files to affected servers.
The flaw stems from a missing file type validation in the plugin's file upload functionality. Successful exploitation could lead to remote code execution, giving attackers full control over the compromised
Continue reading from the source...
Source: The Hacker News
- Critical WooCommerce
- WooCommerce Plugin
- Plugin Flaw
- Flaw Exploited
- Exploited Threat
Most read in this category
Loading article…