• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Unauthenticated file upload via WooCommerce Wholesale Lead Capture wwlc_file_upl

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 23 days ago•0•0•4

    Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.

    Microsoft Sentinel (KQL)

    Tags

    T1190 - Exploit Public-Facing ApplicationT1505.003 - Web ShellTA0003 - PersistenceHTTP RequestFile UploadWindowsMicrosoft Iiskql

    Found in

    • WordPress Plugins Exploited for Remote Code ExecutionLast updated 23 days ago
    • WordPress Plugins Exploited for Remote Code ExecutionLast updated 23 days ago
    • WordPress Plugins Exploited for Remote Code ExecutionLast updated 23 days ago
    • WordPress Plugins Exploited for Remote Code ExecutionLast updated 23 days ago
    • WordPress Plugins Exploited for Remote Code ExecutionLast updated 23 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?