Attackers actively exploited a critical zero-day in the Fancy Product Designer plugin for WordPress, including deployments tied to WooCommerce, by scanning for vulnerable sites and abusing a malicious file upload flaw to achieve remote code execution. The vulnerability allowed unauthenticated attackers to upload executable PHP files, giving them a path to fully compromise affected websites.
Researchers at Wordfence said the activity appeared focused on e-commerce sites, where intruders could steal order data containing customer personally identifiable information and expose merchants to potential PCI-DSS compliance issues. Wordfence observed exploitation beginning on January 30, 2021, and urged site owners to update to Fancy Product Designer version 4.6.9, which was released to address the issue.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
Wordfence observed active exploitation of a critical remote code execution vulnerability in the WordPress Fancy Product Designer plugin beginning on January 30, 2021. Attackers were scanning for vulnerable sites and abusing malicious file uploads to gain full control, with e-commerce stores appearing to be the primary targets.
A patched release, Fancy Product Designer version 4.6.9, was issued to fix the vulnerability. Users were urged to update immediately because the plugin lacked an automatic update mechanism and some configurations could remain exploitable even after deactivation.
Wordfence publicly disclosed the Fancy Product Designer zero-day while it was still under active attack and before a patch was available. The company withheld some technical details but shared indicators of compromise, including attacker IP addresses, to help defenders detect intrusions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.