09/16/2026
A small plugin can create a serious risk for your online store.
Attackers are actively exploiting a vulnerability in WooCommerce Wholesale Lead Capture, a third-party WordPress plugin that could let them upload malicious files and take control of an affected site.
Using this plugin? Here’s what to do:
• Check your version. Versions 2.0.3.1 and earlier are affected.
• Update to the latest patched release. The security fix was introduced in 2.0.3.2.
• Have your site checked for signs of compromise. An update won’t remove an existing backdoor.
This is why ongoing website care matters. Updates, monitoring and reliable backups all play a role in protecting the business behind your website.
At Kingswood Digital, we handle managed WordPress care so you can focus on running your business.
Need help keeping your site maintained and monitored? Talk to Kingswood Digital.
Read the full BleepingComputer report.
https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/