ZeroHour

Search: “cve-2026-27540”

1 stories in the last 30d

CVE-2026-27540 WooCommerce Flaw Exploited

Attackers are actively exploiting CVE-2026-27540, a critical arbitrary file-upload flaw in the WooCommerce Wholesale Lead Capture WordPress plugin.

Attackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture plugin for WordPress. The critical arbitrary file-upload vulnerability lets attackers place malicious files on vulnerable sites, typically enabling webshell deployment or code execution. WordPress sites running the plugin should update immediately.

SOCRadarupdated · 22h agofirst · 1d agoExploit / PoC in the wild 6 sourcesCVE-2026-27540