By industry

Retail & e-commerce security news

All industries →

Today · Wed, 16 Sept 2026

  1. PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

    Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells

    Infosecurity MagazineWordPress
  2. Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

    The Hacker NewsWordPress

Yesterday · Tue, 15 Sept 2026

  1. Hackers target WordPress sites via third-party WooCommerce plugin

    Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.

    BleepingComputerWordPress

Fri, 14 Aug 2026

  1. Metasploit Wrap Up: Lot of summer shells and fit http profiles

    This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads (more details on the [official 6.5 release blog post](https://www.rapid7.com/blog/post/pt-metasploit-framework-6-5-released/)!). Windows on ARM confirm to be the new first-class citizenship thanks to brand-new AArch64 reverse-TCP shells (both inline and staged), so your Snapdragon boxes can join the party too. Last but not least, an important message: *Nyan Nyan Nyan Nyan Nyan Nyan.* New module content (13) Ray Dashboard Logs API Path Traversal Author: Richard Howe Type: Auxiliary Pull request: #21681 contributed by rmhowe425 Path: `gather/ray_dashboard_logs_api_path_traversal` Description: This adds an auxiliary module that leverages a path traversal vulnerability in Ray to list the contents of

    Rapid7 BlogWindows, SonicWall, Linux

Latest retail & e-commerce briefing

Retail & e-commerce Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14

6 stories affecting retail & e-commerce tracked in the last seven days, 3 rated critical, 1 vulnerability added to the CISA Known Exploited catalogue.

Named most often, last 90 days

About retail & e-commerce news

12
Stories
5
In the last 7 days
1
Critical in the last 7 days