Hackers Exploit Critical WooCommerce Plugin Flaw to Take Over WordPress Sites Without Login
Attackers are actively exploiting CVE-2026-27540 (CVSS 9.8), an unauthenticated file-upload flaw in the WooCommerce Wholesale Lead Capture plugin affecting ~6,000 sites, to upload PHP webshells; Wordfence has blocked 100,000+ attempts and the flaw is patched…
Attackers are actively exploiting CVE-2026-27540, a CVSS 9.8 unauthenticated arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture premium plugin, which affects versions 2.0.3.1 and earlier across roughly 6,000 active WordPress installations. The plugin's unauthenticated AJAX handler (wwlc_file_upload_handler, reachable via wp-admin/admin-ajax.php) trusts a client-supplied file_settings allowlist of permitted file types, allowing attackers without any WordPress account to upload PHP webshells such as shell.php, enabling remote code execution. The uploaded webshell reports host details for reconnaissance and enables additional malicious file uploads. The flaw was discovered by researcher Teemu Saarentaus and fixed in plugin version 2.0.3.2, released February 20. Wordfence has blocked more than 100,000 exploit attempts since disclosure, with activity bursts between June 4-17, July 1, and August 30, 2026. Administrators are advised to upgrade to the patched version and audit their sites for rogue .php files.
- CVE-2026-27540 is a CVSS 9.8 unauthenticated arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin
- Affects plugin versions 2.0.3.1 and earlier across approximately 6,000 active installations
- Exploited via the unauthenticated AJAX handler wwlc_file_upload_handler, reachable through wp-admin/admin-ajax.php, which trusts a client-controlled file_settings allowlist
- Attackers upload shell.php webshells without any WordPress account, gaining remote code execution; the webshell performs reconnaissance (host details) and enables further payload uploads
- Wordfence has blocked more than 100,000 exploit attempts, with spikes June 4-17, July 1, and August 30, 2026
- Vulnerability discovered by researcher Teemu Saarentaus
- Patch available in plugin version 2.0.3.2, released February 20
- Administrators urged to upgrade and hunt for rogue .php files on affected sites
Coverage timelineoldest first · each row is one article
- · 9h agoHackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login
Cyber Security News· 60
Attackers exploit CVE-2026-27540 (CVSS 9.8) in WooCommerce Wholesale Lead Capture to upload PHP webshells without authentication.
- · 9h agoHackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors
GBHackers· 75
Attackers actively exploit CVE-2026-27540 (CVSS 9.8) in WooCommerce Wholesale Lead Capture plugin to upload PHP webshells; patch shipped in version 2.0.3.2.
- · 6h agoHackers target WordPress sites via third-party WooCommerce plugin
BleepingComputer· 70
Attackers exploit unauthenticated file-upload flaw CVE-2026-27540 in WooCommerce Wholesale Lead Capture plugin to install PHP webshells; Wordfence blocked 100,000+ attacks.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-27540 | Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1. NVD description · AI analysis pending | 9.0 | 2% |
| — |