ZeroHour
SOCRadarpublished ()ingested ameer
Part of a story covered by 6 sources: “Hackers Actively Exploit WooCommerce Wholesale Lead Capture Flaw CVE-2026-27540 to Plant PHP Webshells on WordPress Sites” — merged summary and timeline →

CVE-2026-27540 WooCommerce Flaw Exploited

highExploit / PoC exploited in the wildimportance 78CVE-2026-27540
AI summary · glm-5.3-flash

Attackers are actively exploiting CVE-2026-27540, a critical arbitrary file-upload flaw in the WooCommerce Wholesale Lead Capture WordPress plugin.

Attackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture plugin for WordPress. The critical arbitrary file-upload vulnerability lets attackers place malicious files on vulnerable sites, typically enabling webshell deployment or code execution. WordPress sites running the plugin should update immediately.

  • CVE-2026-27540 is a critical arbitrary file-upload vulnerability
  • Affects the WooCommerce Wholesale Lead Capture plugin for WordPress
  • Exploitation has been observed in the wild
  • Successful upload can lead to site compromise

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-27540
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd.

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

NVD description · AI analysis pending
9.02%
  • WordPress, E-commerce
Full article

CVE-2026-27540 WooCommerce Flaw Exploited Attackers are actively exploiting CVE-2026-27540 , a critical arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin for WordPress. The flaw allows

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.