Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

2026-09-16T07:23:59Z•00ea41ff687178473816328b97bc61713b667d69143f2f6220771f3a893f99fb
CVE-2026-42016CVE-2026-5430CVE-2026-76461CVE-2026-85706CISA KEVCisco Secure Email GatewayGitLabGiteaMQTTTelegram malwareWSO2WordPressactive exploitationbanking malwarebrowser extensioncloud credential theftconfidential computingcredential theftespionagephishingremote code executionsession hijackingsupply chainweb shellzero-day

What happened

The feed highlights multiple high-impact cybersecurity threats, including active exploitation of critical vulnerabilities in WSO2 API Manager, Cisco Secure Email Gateway, Gitea, GitLab, WooCommerce Wholesale Lead Capture, and other exposed technologies. Reported activity includes unauthenticated remote code execution, arbitrary file upload and web-shell deployment, account takeover, root-level command execution, credential and session-token theft, espionage malware, supply-chain compromise, cloud credential exfiltration, and rapid post-compromise lateral movement. Several entries describe in-w

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
00ea41ff687178473816328b97bc61713b667d69143f2f6220771f3a893f99fb
Enrichment time
2026-09-16T07:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.