Hackers are actively exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture plugin to upload PHP backdoors and gain full control of WordPress sites. Wordfence says it blocked more than 100,000 attack attempts and recommends upgrading to version 2.0.3.2 or later, checking for malicious files, and reviewing logs for exploitation signs. #CVE-2026-27540 #WooCommerceWholesaleLeadCapture #Wordfence #TeemuSaarentaus
Keypoints
- CVE-2026-27540 affects WooCommerce Wholesale Lead Capture plugin versions 2.0.3.1 and older.
- The flaw allows unauthenticated arbitrary file uploads through the wwlc_file_upload_handler AJAX action.
- Attackers can upload PHP webshells and execute code on WordPress sites.
- Wordfence blocked over 100,000 exploitation attempts linked to the vulnerability.
- Admins should update to version 2.0.3.2, review logs, and check for suspicious PHP files or unknown accounts.