The critical security failure could leave more than 100,000 WordPress sites at risk


  • A defect in the WooCommerce wishes list allows threat actors to load arbitrary files
  • Since the files can be malicious, they could take care of a website
  • A patch has not yet been launched, so users must be careful

A critical severity vulnerability in a popular WordPress complement is possibly exposing hundreds of thousands of websites to different risks, including the complete acquisition of the website.

Patchstack’s security researchers have affirmed that the WOOCOMMERCE WISPER List carried an arbitrary file load failure, which allowed the actors to load malicious files to the underlying server without authentication.

Leave a Comment

Your email address will not be published. Required fields are marked *