WooCommerce 플러그인에서 발견된 취약점으로 해커들이 PHP 웹 쉘을 심고 있습니다.
해커들이 WooCommerce Wholesale Lead Capture 플러그인의 심각한 보안 취약점을 악용하여 PHP 백도어를 업로드하고 원격 코드 실행을 가능하게 하고 있습니다. 이 프리미엄 WordPress 플러그인은 6,000개 이상의 활성 설치가 있으며, 인증되지 않은 공격자가 이 취약점을 이용할 수 있습니다. Wordfence에 따르면, 이 회사는 이미 해당 공격을 차단해 왔습니다.
Hackers exploit a vulnerability in WooCommerce to upload PHP web shells.
Attackers are exploiting a critical security flaw in the WooCommerce Wholesale Lead Capture plugin, allowing them to upload PHP backdoors and achieve remote code execution. This premium WordPress plugin has over 6,000 active installations and can be leveraged by unauthenticated attackers. Wordfence notes that they have already blocked numerous attempts related to this vulnerability.