← Back to feed
vendor Wordfence Blog

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

Wordfence Blog WordPress

On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premiu...

T1190
Read the full story Wordfence Blog →

Related Coverage

vendor Transforming Bedrock Guardrails events into OCSF with CloudWatch AWS Security Blog · Sep 21 vendor Python Workers are now generally available Cloudflare Blog · Sep 21 vendor Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server Wordfence Blog · Sep 18