ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

Hackers Exploit Critical WooCommerce Plugin Flaw to Take Over WordPress Sites Without Login

highExploit / PoCexploited in the wildimportance 75CVE-2026-27540
What's new: BleepingComputer's later report added new details: the vulnerability was discovered by researcher Teemu Saarentaus, the fix shipped in version 2.0.3.2 on February 20, and the shell.php webshell conducts reconnaissance by reporting host details and enables additional malicious file uploads. All other facts are consistent across the three reports and the prior summary.
Merged summary · glm-5.3 · rewritten as coverage arrives

Attackers are actively exploiting CVE-2026-27540 (CVSS 9.8), an unauthenticated file-upload flaw in the WooCommerce Wholesale Lead Capture plugin affecting ~6,000 sites, to upload PHP webshells; Wordfence has blocked 100,000+ attempts and the flaw is patched…

Attackers are actively exploiting CVE-2026-27540, a CVSS 9.8 unauthenticated arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture premium plugin, which affects versions 2.0.3.1 and earlier across roughly 6,000 active WordPress installations. The plugin's unauthenticated AJAX handler (wwlc_file_upload_handler, reachable via wp-admin/admin-ajax.php) trusts a client-supplied file_settings allowlist of permitted file types, allowing attackers without any WordPress account to upload PHP webshells such as shell.php, enabling remote code execution. The uploaded webshell reports host details for reconnaissance and enables additional malicious file uploads. The flaw was discovered by researcher Teemu Saarentaus and fixed in plugin version 2.0.3.2, released February 20. Wordfence has blocked more than 100,000 exploit attempts since disclosure, with activity bursts between June 4-17, July 1, and August 30, 2026. Administrators are advised to upgrade to the patched version and audit their sites for rogue .php files.

  • CVE-2026-27540 is a CVSS 9.8 unauthenticated arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin
  • Affects plugin versions 2.0.3.1 and earlier across approximately 6,000 active installations
  • Exploited via the unauthenticated AJAX handler wwlc_file_upload_handler, reachable through wp-admin/admin-ajax.php, which trusts a client-controlled file_settings allowlist
  • Attackers upload shell.php webshells without any WordPress account, gaining remote code execution; the webshell performs reconnaissance (host details) and enables further payload uploads
  • Wordfence has blocked more than 100,000 exploit attempts, with spikes June 4-17, July 1, and August 30, 2026
  • Vulnerability discovered by researcher Teemu Saarentaus
  • Patch available in plugin version 2.0.3.2, released February 20
  • Administrators urged to upgrade and hunt for rogue .php files on affected sites

Coverage timeline

  1. · 9h ago
    Cyber Security News· 60
    Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login

    Attackers exploit CVE-2026-27540 (CVSS 9.8) in WooCommerce Wholesale Lead Capture to upload PHP webshells without authentication.

  2. · 9h ago
    GBHackers· 75
    Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

    Attackers actively exploit CVE-2026-27540 (CVSS 9.8) in WooCommerce Wholesale Lead Capture plugin to upload PHP webshells; patch shipped in version 2.0.3.2.

  3. · 6h ago
    BleepingComputer· 70
    Hackers target WordPress sites via third-party WooCommerce plugin

    Attackers exploit unauthenticated file-upload flaw CVE-2026-27540 in WooCommerce Wholesale Lead Capture plugin to install PHP webshells; Wordfence blocked 100,000+ attacks.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-27540
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd.

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

NVD description · AI analysis pending
9.02%
  • WordPress, E-commerce