Find notable cyber news and cases, enriched with sources, timelines, and signals.

WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)

Vulnerability
First reported
Last updated
Happening score
H score 16
2 unique sources, 2 articles

Summary

Hide ▲

CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell upload and complete site compromise. The flaw was fixed in version 2.0.3.2. Site operators should treat exposed installs as high risk until patched.

Related Happenings

WordPress core Click2Shell security flaw

Vulnerability
H score37 First: 18.09.2026 19:56 Last: 18.09.2026 19:56 Sources 1

About this happening: WordPress core’s Click2Shell vulnerability is a CSRF chain that can let a logged-in administrator open a crafted URL, force-install a theme from the WordPres...

Latest development: 21.09.2026 21:23

pwn.ai publishes technical details and a complete proof-of-concept for Click2Shell, a WordPress Core CSRF chain that can let a logged-in administrator open a crafted URL, force-install a theme from the WordPress.org catalog, and execute arbitrary PHP on the server. The write-up says the flaw affects WordPress Core 7.1.0 and earlier, and that the underlying issue can be leveraged to force-install other vulnerable themes as well.

WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave

Exploitation Wave
H score16 First: 15.09.2026 17:45 Last: 15.09.2026 17:45 Sources 1

How related: Wordfence said its firewall had blocked more than 100,000 exploitation attempts against CVE-2026-27540 in WooCommerce Wholesale Lead Capture, a premium plugin from Rymera Web Co with an estimated 6000 active installations.

About this happening: CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...

Timeline

  1. 15.09.2026 17:45 2 articles · 6d ago

    WooCommerce Wholesale Lead Capture 2.0.3.2 fixes CVE-2026-27540

    Mitigation Patch Update

    WooCommerce Wholesale Lead Capture version 2.0.3.2 was released on February 20 to fix CVE-2026-27540, an unauthenticated arbitrary file-upload flaw in the premium WordPress plugin. The issue let a forged file_settings parameter influence the wwlc_file_upload_handler AJAX action so that php could be added to the permitted file types and PHP webshells could be uploaded.

    Show sources
  2. 15.09.2026 17:45 2 articles · 6d ago

    Wordfence warns of active CVE-2026-27540 exploitation against WordPress sites

    Initial Disclosure

    Wordfence warns that WordPress sites running the WooCommerce Wholesale Lead Capture premium plugin are being actively exploited for CVE-2026-27540, with its firewall blocking over 100,000 attacks. The observed activity spiked between June 4 and June 17, then again on July 1 and August 30, and attackers used the plugin's upload path to drop .php webshells that report host details and can write additional malicious files.

    Show sources