WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)
Security Patch Release
Summary
Hide ▲
Show ▼
The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upload PHP webshells to WordPress sites. The update covered version 2.0.3.1 and older and landed on February 20. Site operators were told to upgrade to 2.0.3.2 or later and look for suspicious /wp-admin/admin-ajax.php activity and unexpected PHP files.
Related Happenings
WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave
Exploitation Wave
H score34
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
How related:
Wordfence reports that exploitation activity spiked between June 4 and June 17, and on July 1 and August 30.
About this happening:
CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...
WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave
Exploitation WaveHow related: Wordfence reports that exploitation activity spiked between June 4 and June 17, and on July 1 and August 30.
About this happening: CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch Release
H score27
First: 20.08.2026 09:04
Last: 20.08.2026 09:04
Sources 1
About this happening:
Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch ReleaseAbout this happening: Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch Release
H score67
First: 17.08.2026 16:30
Last: 17.08.2026 16:30
Sources 1
About this happening:
Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch ReleaseAbout this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)
Security Patch Release
H score66
First: 18.07.2026 00:20
Last: 18.07.2026 00:20
Sources 1
About this happening:
WordPress Core patched a pre-auth RCE on July 17, 2026 with 6.9.5 and 7.0.2, and the release also enabled forced automatic updates for supported installati...
WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)
Security Patch ReleaseAbout this happening: WordPress Core patched a pre-auth RCE on July 17, 2026 with 6.9.5 and 7.0.2, and the release also enabled forced automatic updates for supported installati...
Latest development: 21.07.2026 19:41
WordPress sites saw wp2shell probing at 23:29 UTC on July 17, followed 13 minutes later by a clear SQL injection attempt; Wiz also described attacks that mass-scanned vulnerable installations, abused plugin upload functionality, installed PHP webshells, and targeted wp-config through admin-ajax.php.
WP Maps Pro 6.1.1 security patch for CVE-2026-8732
Security Patch Release
H score49
First: 31.05.2026 17:06
Last: 31.05.2026 17:06
Sources 1
About this happening:
WP Maps Pro 6.1.1 was released to fix CVE-2026-8732, giving WordPress administrators a patch for a flaw that enabled unauthenticated administrator-account creation. Th...
WP Maps Pro 6.1.1 security patch for CVE-2026-8732
Security Patch ReleaseAbout this happening: WP Maps Pro 6.1.1 was released to fix CVE-2026-8732, giving WordPress administrators a patch for a flaw that enabled unauthenticated administrator-account creation. Th...
Timeline
-
15.09.2026 17:45 2 articles · 2h ago
WooCommerce Wholesale Lead Capture 2.0.3.2 closes CVE-2026-27540
Mitigation Patch UpdateWooCommerce Wholesale Lead Capture version 2.0.3.2 was released on February 20, 2026 to fix CVE-2026-27540, an unauthenticated arbitrary file-upload flaw in version 2.0.3.1 and older. The issue exposed the `wwlc_file_upload_handler` AJAX action and let a user-controlled `file_settings` parameter admit `.php` uploads, enabling PHP webshell upload and code execution; administrators were advised to upgrade to 2.0.3.2 or later.
Show sources
- Hackers target WordPress sites via third-party WooCommerce plugin — www.bleepingcomputer.com — 15.09.2026 17:45
- Hackers target WordPress sites via third-party WooCommerce plugin — www.bleepingcomputer.com — 15.09.2026 17:45
-
15.09.2026 17:45 1 articles · 2h ago
Wordfence warns of active CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture
Initial DisclosureWordfence warned that hackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture premium plugin for WordPress, using a forged `file_settings` value and a malicious `.php` upload through `wwlc_file_upload_handler` to place a PHP webshell that can report host details, support reconnaissance, and write additional malicious files. Wordfence said its firewall blocked over 100,000 attacks and noted exploitation spikes between June 4 and June 17, as well as on July 1 and August 30.
Show sources
- Hackers target WordPress sites via third-party WooCommerce plugin — www.bleepingcomputer.com — 15.09.2026 17:45