Find notable cyber news and cases, enriched with sources, timelines, and signals.

WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)

Security Patch Release
First reported
Last updated
Happening score
H score 9
3 unique sources, 3 articles

Summary

Hide ▲

The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upload PHP webshells to WordPress sites. The update covered version 2.0.3.1 and older and landed on February 20. Site operators were told to upgrade to 2.0.3.2 or later and look for suspicious /wp-admin/admin-ajax.php activity and unexpected PHP files.

Related Happenings

WordPress core security release (7.1.1)

Security Patch Release
H score45 First: 18.09.2026 19:56 Last: 18.09.2026 19:56 Sources 1

About this happening: WordPress 7.1.1 is a security release that fixed the Click2Shell WordPress Core flaw, a CSRF issue that could let a logged-in administrator open a crafted...

WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave

Exploitation Wave
H score16 First: 15.09.2026 17:45 Last: 15.09.2026 17:45 Sources 1

How related: The WordPress security company said it has blocked over 100,000 exploit attempts targeting the vulnerability since June 2026, with 99 of those attack attempts recorded over the past 24 hours.

About this happening: CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...

Elementor Pro 4.2.2 security update for CVE-2026-32475

Security Patch Release
H score27 First: 20.08.2026 09:04 Last: 20.08.2026 09:04 Sources 1

About this happening: Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...

Cozmoslabs security patch release for CVE-2026-15826

Security Patch Release
H score67 First: 17.08.2026 16:30 Last: 17.08.2026 16:30 Sources 1

About this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...

BdThemes hit by network compromise

Incident
H score17 First: 10.08.2026 17:30 Last: 10.08.2026 17:30 Sources 1

About this happening: A BdThemes WordPress plugin supply-chain compromise let attackers poison the Biggopti promotional API feed and trigger browser-executed code in wp-admin pages, lea...

Timeline

  1. 15.09.2026 17:45 4 articles · 6d ago

    WooCommerce Wholesale Lead Capture 2.0.3.2 closes CVE-2026-27540

    Mitigation Patch Update

    WooCommerce Wholesale Lead Capture version 2.0.3.2 was released on February 20, 2026 to fix CVE-2026-27540, an unauthenticated arbitrary file-upload flaw in version 2.0.3.1 and older. The issue exposed the `wwlc_file_upload_handler` AJAX action and let a user-controlled `file_settings` parameter admit `.php` uploads, enabling PHP webshell upload and code execution; administrators were advised to upgrade to 2.0.3.2 or later.

    Show sources
  2. 15.09.2026 17:45 1 articles · 6d ago

    Wordfence warns of active CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture

    Initial Disclosure

    Wordfence warned that hackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture premium plugin for WordPress, using a forged `file_settings` value and a malicious `.php` upload through `wwlc_file_upload_handler` to place a PHP webshell that can report host details, support reconnaissance, and write additional malicious files. Wordfence said its firewall blocked over 100,000 attacks and noted exploitation spikes between June 4 and June 17, as well as on July 1 and August 30.

    Show sources