Attackers are actively exploiting a critical vulnerability in WooCommerce Wholesale Lead Capture Plugin, which allows unauthenticated arbitrary file uploads due to missing file type validation in all versions up to and including. This makes it possible for attackers to upload files with malicious extensions such a remote script resource, allowing remote code execution. The vulnerable plugin exposes an AJAX action that processes these uploads and is reachable by unauthenticated visitors.
The handler does check the uploaded file's extension against a list of allowed file types, but this list is read directly from the request rather than from the form's server-side configuration. An attacker can include php in their own list of allowed file types to bypass the restriction and upload a file with a remote script resource extension.[/subscribe_to_unlock_form]
Attackers are actively exploiting a critical vulnerability in WooCommerce Wholesale Lead Capture Plugin, which allows unauthenticated arbitrary file uploads due to missing file type validation in all versions up to and including. This makes it possible for attackers to upload files with malicious extensions such a remote script resource, allowing remote code execution. The vulnerable plugin exposes an AJAX action that processes these uploads and is reachable by unauthenticated visitors.
The handler does check the uploaded file's extension against a list of allowed file types, but this list is read directly from the request rather than from the form's server-side configuration. An attacker can include php in their own list of allowed file types to bypass the restriction and upload a file with a remote script resource extension.[emaillocker id="1283"]
The impact of this vulnerability is severe, as it allows attackers to write a PHP webshell to the site and execute arbitrary code, which can be leveraged to create administrator accounts, exfiltrate data, or take complete control of the site. It's essential for users to update their sites with the latest patched version of WooCommerce Wholesale Lead Capture Plugin, version, as soon as possible.
We recommend you to update WooCommerce Wholesale Lead Capture to version 2.0.3.2.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1190 | Exploit Public | Facing Application- |
| Execution | T1204.002 | User Execution | Malicious File |
| Persistence | T1543.003 | Create or Modify System Process | Windows Service |
The following reports contain further technical details:
[/emaillocker]