CVE-2026-27540 WooCommerce Flaw Exploited
Attackers are actively exploiting CVE-2026-27540, a critical arbitrary file-upload flaw in the WooCommerce Wholesale Lead Capture WordPress plugin.
Attackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture plugin for WordPress. The critical arbitrary file-upload vulnerability lets attackers place malicious files on vulnerable sites, typically enabling webshell deployment or code execution. WordPress sites running the plugin should update immediately.
- CVE-2026-27540 is a critical arbitrary file-upload vulnerability
- Affects the WooCommerce Wholesale Lead Capture plugin for WordPress
- Exploitation has been observed in the wild
- Successful upload can lead to site compromise
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-27540 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1. NVD description · AI analysis pending | 9.0 | 2% |
| — |
CVE-2026-27540 WooCommerce Flaw Exploited Attackers are actively exploiting CVE-2026-27540 , a critical arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin for WordPress. The flaw allows
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.