• News/
  • https://www.bleepingcomputer.com/news/security/woocommerce-admins-targeted-by-fake-security-patches-that-hijack-sites/

WooCommerce admins targeted by fake security patches that hijack sites

BleepingComputer
·
Bill Toulas
·
Published Apr 26, 2025
·
Updated

A large-scale phishing campaign targets WooCommerce users with a fake security alert urging them to download a "critical patch" that adds a Wordpress backdoor to the site. Recipients that take the bait and download the update are actually installing a malicious plugin that creates a hidden admin account on their website, downloads web shell payloads, and maintains persistent access. The campaign, which was discovered by Patchstack researchers, appears to be a continuation of a similar operation in late 2023 that targeted WordPress users with a fake patch for a made-up vulnerability. Patchstack says both campaigns used an unusual set of web shells, identical payload hiding methods, and similar email content. The emails targeting WordPress admins spoof the popular WooCommerce e-commerce plugin, using the address 'help@security-woocommerce[.]com.' Recipients are informed that their websites were targeted by hackers attempting to exploit an 'unauthenticated administrative access' vulnerability. To protect their online stores and data, recipients are advised to download a patch using the embedded button, with step-by-step instructions on how to install it included in the message. "We are contacting you regarding a critical security vulnerability found in WooCommerce platform on April 14, 2025," reads the phishing emails. "Warning: Our latest security scan, carried out on April 21, 2025, has confirmed that this critical vulnerability directly impacts your website." "We strongly ad...

Read full article

Affected Software

4 affected components
WooCommerce Woocommerce
WordPress WordPress
WooCommerce Woocommerce
WordPress WordPress
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203