WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at risk of PHP webshell uploads and full compromise.
Related Happenings
WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)
Security Patch Release
H score9
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
How related:
The flaw was disclosed and patched on February 20 in version 2.0.3.2.
About this happening:
The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...
WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)
Security Patch ReleaseHow related: The flaw was disclosed and patched on February 20 in version 2.0.3.2.
About this happening: The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...
WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)
Vulnerability
H score16
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
How related:
Wordfence found the list is read straight from the request rather than from the form's server-side configuration, so an unauthenticated attacker can include php in a list of their own and upload an executable, turning an arbitrary file upload into remote code execution.
About this happening:
CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell...
WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)
VulnerabilityHow related: Wordfence found the list is read straight from the request rather than from the form's server-side configuration, so an unauthenticated attacker can include php in a list of their own and upload an executable, turning an arbitrary file upload into remote code execution.
About this happening: CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation Wave
H score53
First: 05.09.2026 10:31
Last: 05.09.2026 10:31
Sources 1
About this happening:
PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave
Exploitation WaveAbout this happening: PaperCut exploitation tied to CVE-2026-81578 and CVE-2026-82078 remains an active exploitation wave against PaperCut NG/MF servers. Arctic Wolf previously...
Timeline
-
15.09.2026 17:45 4 articles · 6d ago
Wordfence blocks over 100,000 CVE-2026-27540 exploitation attempts against WooCommerce Wholesale Lead Capture
Campaign Scope UpdateWordfence says its web application firewall blocked over 100,000 attacks linked to CVE-2026-27540 against the WooCommerce Wholesale Lead Capture premium plugin for WordPress, where unauthenticated exploitation of the wwlc_file_upload_handler AJAX action and forged file_settings parameters can upload PHP webshells and lead to complete site compromise. The same reporting says exploitation activity spiked between June 4 and June 17, and again on July 1 and August 30, and advises upgrading to version 2.0.3.2 or later while checking for unexpected PHP files, suspicious /wp-admin/admin-ajax.php requests, and unknown administrator accounts.
Show sources
- Hackers target WordPress sites via third-party WooCommerce plugin — www.bleepingcomputer.com — 15.09.2026 17:45
- Hackers target WordPress sites via third-party WooCommerce plugin — www.bleepingcomputer.com — 15.09.2026 17:45
- Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells — thehackernews.com — 16.09.2026 08:48
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug — www.infosecurity-magazine.com — 16.09.2026 18:00