• Skip to primary navigation
  • Skip to content
  • Skip to primary sidebar
  • Skip to footer

Sucuri Blog

Website Security News

  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Enterprise Website Security
    • Multisite Solutions
  • Features
    • Detection
    • Protection
    • Performance
    • Response
    • Backups
  • Partners
    • Agency Solutions
    • Partners
    • Referral Program
    • Ecommerce
  • Resources
    • Guides
    • Webinars
    • Infographics
    • SiteCheck
    • Reports
    • Email Courses
  • Immediate Help
  • Login

Search Results for: woocommerce

WooCommerce Credit Card Skimmer Uses Telegram Bot to Exfiltrate Stolen Data

June 16, 2022Ben Martin

WooCommerce Credit Card Skimmer Uses Telegram Bot to Exfiltrate Stolen Data

Our story starts like many others told on this blog: A new client came to us with reported cases of credit card theft on their eCommerce website. The website owner had received complaints from several customers who reported bogus transactions on their cards shortly after…

Read More about WooCommerce Credit Card Skimmer Uses Telegram Bot to Exfiltrate Stolen Data

Analyzing a WooCommerce credit card stealer

May 19, 2022Liam Smith

Analyzing a WooCommerce Credit Card Skimmer

The number of credit card skimmers targeting WooCommerce websites has skyrocketed over the past year, and threat actors have become increasingly creative in the different ways they obfuscate their payloads…

Read More about Analyzing a WooCommerce Credit Card Skimmer

WooCommerce Credit Card Stealer Concealed in Fake JPG

May 3, 2022Matt Morrow

WooCommerce Credit Card Skimmers Concealed In Fake Images

Our research and remediation teams have noticed an increase in WooCommerce credit card skimmers on client sites over the past few years, as detailed in past blog posts. Due to…

Read More about WooCommerce Credit Card Skimmers Concealed In Fake Images

February 2, 2022Ben Martin

WooCommerce Skimmer Uses Fake Fonts and Favicon to Steal CC Details

The holidays are always a busy time for ecommerce stores. Dealing with an influx of Christmas shoppers, holiday sales and inventory, shipping, and at times, also hackers. Today’s investigation starts…

Read More about WooCommerce Skimmer Uses Fake Fonts and Favicon to Steal CC Details

December 6, 2021Ben Martin

WooCommerce Credit Card Swiper Injected Into Random Plugin Files

It’s that time of year again! While website owners always need to be on guard, the holidays season is when online scams and credit card theft are most rampant. Administrators…

Read More about WooCommerce Credit Card Swiper Injected Into Random Plugin Files

Online Credit Card Theft - A Brief Overview of Online Fraud and Abuse

November 8, 2021Ben Martin

WooCommerce Skimmer Spoofs Checkout Page

Recently a client of ours was reporting a bogus checkout page appearing on their website. When trying to access their “my-account” page an unfamiliar prompt appeared in their browser soliciting…

Read More about WooCommerce Skimmer Spoofs Checkout Page

WooCommerce Credit Card Swiper Hides in Plain Sight

May 28, 2021Ben Martin

WooCommerce Credit Card Skimmer Hides in Plain Sight

Recently, a client’s customers were receiving a warning from their anti-virus software when they navigated to the checkout page of the client’s ecommerce website. Antivirus software such as Kaspersky and…

Read More about WooCommerce Credit Card Skimmer Hides in Plain Sight

Reverse String WooCommerce

July 27, 2020Ben Martin

Reverse String WooCommerce WordPress Credit Card Swiper

As 2020 continues to be the worst year in almost anybody’s lifetime, allow me to take this opportunity to stoke the fires of your existential dread even further. As a…

Read More about Reverse String WooCommerce WordPress Credit Card Swiper

WordPress Vulnerability

June 22, 2020John Castro

Cross Site Scripting in YITH WooCommerce Ajax Product Filter

During a routine research audit for our Sucuri Web Application Firewall, we discovered a cross-site scripting (XSS) vulnerability affecting 100,000+ users of the YITH WooCommerce Ajax Product Filter  plugin. Current…

Read More about Cross Site Scripting in YITH WooCommerce Ajax Product Filter

PinnacleCart Server-Side Skimmer & Backdoor

May 15, 2020Luke Leal

WordPress Malware Collects Sensitive WooCommerce Data

During a recent investigation, our team found malicious code that reveals how attackers are performing reconnaissance to identify if sites are actively using WooCommerce in a compromised hosting environment. These…

Read More about WordPress Malware Collects Sensitive WooCommerce Data

Labs Note

September 18, 2019John Castro

Unauthenticated settings update in woocommerce-ajax-filters

woocommerce-ajax-filters, which currently has over 10,000 installations (versions <=1.3.6) allows unauthenticated attackers to arbitrarily update all the plugin options and redirect any user to an external malicious URL when the…

Read More about Unauthenticated settings update in woocommerce-ajax-filters

Primary Sidebar

Socialize With Sucuri

We're actively engaged across multiple platforms. Follow us and let's connect!

  • Facebook
  • Twitter
  • LinkedIn
  • YouTube
  • Instagram
  • RSS Feed

Join Over 20,000 Subscribers!

Footer

Products

  • Website Firewall
  • Website AntiVirus
  • Website Backups
  • WordPress Security
  • Enterprise Services

Solutions

  • DDos Protection
  • Malware Detection
  • Malware Removal
  • Malware Prevention
  • Blacklist Removal

Support

  • Blog
  • Knowledge Base
  • SiteCheck
  • Research Labs
  • FAQ

Company

  • About
  • Media
  • Events
  • Employment
  • Contact
  • Testimonials
  • Facebook
  • Twitter
  • LinkedIn
  • Instagram

Customer Login

Sucuri Home

  • Terms of Use
  • Privacy Policy
  • Frequently Asked Questions

© 2022 Sucuri Inc. All rights reserved

Sucuri Cookie Policy
See our policy>>

Our website uses cookies, which help us to improve our site and enables us to deliver the best possible service and customer experience.