Follow the latest coverage, related explainers and connected technology stories.
Attackers are exploiting an undocumented critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload malicious PHP files and potentially take control of WordPress sites. Wordfence has blocked more than 100,000 attacks, while administrators should update to version 2.0.3.2 or later and check for signs of compromise.