Hackers are using a WordPress plugin flaw to break into websites right now
Hackers are actively taking advantage of a serious flaw in a paid add-on used by some WordPress online stores. If left unpatched, attackers may be able to quietly gain control of affected websites and use them for fraud, data theft, or further attacks.
Who is at risk
Website owners and businesses using WordPress with the WooCommerce Wholesale Lead Capture premium plugin are most at risk.
What to watch for
Watch for unexpected website changes, new unknown admin accounts, strange files, redirects, or store behavior that seems unusual.
What to do
Immediately disable or update the WooCommerce Wholesale Lead Capture plugin, check for unknown admin users or recent file changes, and contact your website support provider if anything looks suspicious.
