Stuart Neal
Director of Operations at Nextgen Marketing
We have worked with Vitalli and his team for well over a year now and will continue to do so in the future.
Having the confidence in an agency that allowed us to scale up and down development resources, as and when needed, has really made a positive difference to our agency.
Home / Blog / News / A WooCommerce plugin is being actively exploited right now. Check if your clients run it
To be clear upfront: this isn’t a WooCommerce core vulnerability. It’s in Wholesale Lead Capture Plugin for WooCommerce, a premium third-party plugin with an estimated 6,000 active installs, and it’s currently being actively exploited (per Wordfence’s disclosure). This is exactly the kind of niche, low-visibility plugin that ongoing plugin and security maintenance is designed to catch before it becomes an incident.
If you’re on one of our maintenance plans, we’ve already checked your sites against this plugin — if it’s there, it’s updated, and it’s logged in your monthly maintenance report. Nothing for you to do. If you’re not on a plan, this is exactly the failure mode one is meant to prevent: a plugin nobody remembers installing, quietly running until it’s the one under active attack.
Source: Wordfence