Unauthenticated file upload via WooCommerce Wholesale Lead Capture wwlc_file_upl
Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.
Microsoft Sentinel (KQL)

