A large-scale phishing campaign has targeted WooCommerce, sending fake security alerts urging them to download a "critical update," which ultimately installs a WordPress backdoor on their website.

Users who are tricked into downloading the supposed patch end up installing a malicious plugin. This creates a hidden administrator account, installs web shells , and grants permanent access to the attackers.
This campaign, detected by researchers at Patchstack, appears to be a follow-up to a similar attack that occurred in late 2023 and targeted WordPress via a fake patch for a non-existent vulnerability.
See also: Scallywag: New ad-fraud campaign uses WordPress plugins
According to Patchstack, in both cases the same strange web shells were used, similar techniques for hiding the malicious payload, and similar content in the phishing emails.
WooCommerce: Fake security alert
Phishing emails sent to WordPress administrators attempt to mimic official WooCommerce communication, displaying the sender address 'help@security-woocommerce[.]com'.
The messages state that recipients’ websites have been targeted by hackers, who are attempting to exploit a vulnerability that allows “unauthorized administrator access.” To protect their stores and data, administrators are urged to download an update via a button in the email, with installation instructions provided in the message itself.
The phishing emails state: “We are informing you of a critical security vulnerability identified in the WooCommerce platform on April 14, 2025… According to our last security audit on April 21, 2025, this vulnerability directly affects your website.”
Finally, the messages urge recipients to act immediately: “We recommend that you take immediate steps to protect your store and your data.”
See also: WordPress Plugin Vulnerability with 100,000+ Installs is Actively Exploited
When victims click the “Get Update” button, they are redirected to a website that mimics WooCommerce, using the deceptive domain “woocommėrce[.]com”, which differs from the regular woocommerce.com by only one character. This malicious website implements a technique known as a homograph attack, replacing the letter “e” with the Lithuanian “ė”, a change so small that it can easily go unnoticed.

What happens after infection?
After the victim installs the fake update (“authbypass-update-31297-id.zip”), a cronjob , which runs every minute and attempts to create a new administrative account.
The malicious plugin then sends an HTTP GET request to the website 'woocommerce-services[.]com/wpapi', through which it downloads a second payload. This payload installs several PHP-based web shells into the 'wp-content/uploads/' folder (e.g. PAS-Form, p0wny, and WSO).
According to Patchstack, the web shells installed through the attack give hackers complete control over the website. They can be exploited to inject ads, redirect visitors to malicious pages, join the server to DDoS botnets, steal payment data , or even execute ransomware.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
To reduce the chances of detection, the malicious plugin is automatically removed from the list of active plugins and simultaneously hides the administrative account it created.
See also: Hackers exploit vulnerability in OttoKit WordPress plugin
Patchstack urges website administrators to look for signs of a breach, such as admin accounts with random eight-character names, unusual cronjobs, the existence of a folder named 'authbypass-update' , and outbound activity to woocommerce-services[.]com, woocommerce-api[.]com, and woocommerce-help[.]com.
However, the company emphasizes that cybercriminals tend to change these characteristics as soon as they are revealed by public research, so checks should not be limited to specific known patterns.
WordPress Security
WordPress website security requires a multi-pronged approach to protect against potential threats. One of the key strategies includes regularly updating plugins and themes to ensure that any security vulnerabilities have been patched. Using strong passwords and enabling two-factor authentication adds an extra layer of security. Additionally, regularly backing up your website can protect your data in the event of an attack.
See also: 'DollyWay' malware campaign compromised 20,000 WordPress sites
It is also recommended to install a powerful security plugin that offers features such as firewall protection, malware , and brute force attack prevention.
Source: www.bleepingcomputer.com
