By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Hackers Exploit WooCommerce Plugin Vulnerability
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress, a widely used e-commerce extension. This exploit allows attackers to upload a PHP backdoor onto compromised websites. The vulnerability, identified as CVE-2024-3289, is rated as critical and has been actively exploited in the wild since at least May 2024. The plugin, designed to facilitate wholesale purchasing for businesses using the WooCommerce platform, has seen over 600 installations. The security flaw resides in the plugin's handling of user-uploaded files, specifically its failure to properly sanitize filenames. This oversight enables attackers to bypass security checks and upload arbitrary files, including malicious PHP scripts. Once a PHP backdoor is uploaded, it can grant attackers persistent access to the website's backend, allowing them to steal sensitive data, deface the site, or use the server for further malicious activities. The vulnerability was discovered and reported by security researchers at Wordfence, a prominent WordPress security firm. Wordfence's investigation revealed that the attackers are leveraging the vulnerability to gain unauthorized access and install a backdoor named 'wp-backdoor.php'. This backdoor is designed to execute arbitrary PHP code, effectively giving the attacker full control over the compromised WordPress installation. The developers of the WooCommerce Wholesale Lead Capture plugin have released a patch to address the vulnerability. Users are strongly advised to update the plugin to the latest version, 2.1.5, immediately to mitigate the risk of exploitation. The attack chain typically involves an unauthenticated attacker accessing a vulnerable endpoint within the plugin. By manipulating the 'file' parameter in a POST request, they can upload a malicious file. The plugin's inadequate validation of the uploaded file's extension and content allows the PHP backdoor to be saved and executed. This incident highlights the ongoing threat posed by vulnerabilities in third-party plugins, which are a common attack vector for WordPress websites. The sheer number of plugins available for WordPress, coupled with varying levels of developer security practices, creates a complex ecosystem where a single vulnerable plugin can impact thousands of sites. The WooCommerce Wholesale Lead Capture plugin is specifically designed for businesses that operate a wholesale model within their WooCommerce store. It typically offers features such as tiered pricing, minimum order quantities, and dedicated wholesale user roles, streamlining the process for business-to-business transactions. The active exploitation of this vulnerability underscores the importance of proactive security measures for website administrators. These measures include keeping all plugins, themes, and WordPress core updated, using strong, unique passwords, implementing security plugins with firewall and malware scanning capabilities, and regularly backing up website data. The critical nature of CVE-2024-3289 means that any website using an unpatched version of the WooCommerce Wholesale Lead Capture plugin is at immediate risk. The ease with which attackers can exploit this flaw, requiring no prior authentication, makes it a particularly dangerous threat.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.