Find notable cyber news and cases, enriched with sources, timelines, and signals.

WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)

Vulnerability
First reported
Last updated
Happening score
H score 8
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell upload and complete site compromise. The flaw was fixed in version 2.0.3.2. Site operators should treat exposed installs as high risk until patched.

Related Happenings

WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave

Exploitation Wave
H score34 First: 15.09.2026 17:45 Last: 15.09.2026 17:45 Sources 1

How related: Wordfence reports that exploitation activity spiked between June 4 and June 17, and on July 1 and August 30.

About this happening: CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...

Timeline

  1. 15.09.2026 17:45 1 articles · 2h ago

    WooCommerce Wholesale Lead Capture 2.0.3.2 fixes CVE-2026-27540

    Mitigation Patch Update

    WooCommerce Wholesale Lead Capture version 2.0.3.2 was released on February 20 to fix CVE-2026-27540, an unauthenticated arbitrary file-upload flaw in the premium WordPress plugin. The issue let a forged file_settings parameter influence the wwlc_file_upload_handler AJAX action so that php could be added to the permitted file types and PHP webshells could be uploaded.

    Show sources
  2. 15.09.2026 17:45 2 articles · 2h ago

    Wordfence warns of active CVE-2026-27540 exploitation against WordPress sites

    Initial Disclosure

    Wordfence warns that WordPress sites running the WooCommerce Wholesale Lead Capture premium plugin are being actively exploited for CVE-2026-27540, with its firewall blocking over 100,000 attacks. The observed activity spiked between June 4 and June 17, then again on July 1 and August 30, and attackers used the plugin's upload path to drop .php webshells that report host details and can write additional malicious files.

    Show sources