Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress, allowing them to upload PHP backdoors and potentially compromise entire websites, with further coverage provided by Bleeping Computer.The vulnerability, tracked as CVE-2026-27540, affects versions 2.0.3.1 and older of the plugin. It is an unauthenticated arbitrary file-upload flaw that enables attackers to upload PHP webshells by exploiting an exposed AJAX action, wwlc_file_upload_handler. This flaw allows attackers to add "php" to an allowlist of file extensions, enabling the upload of executable PHP files. The vulnerability was patched in version 2.0.3.2, released on February 20. However, security firm Wordfence reported blocking over 100,000 attacks exploiting this flaw, with exploitation activity peaking between June 4-17 and July 1-August 30.Attackers use the uploaded webshell for reconnaissance and to deploy additional malicious payloads. Administrators are advised to update to the latest plugin version, block malicious IP addresses, check upload directories for suspicious PHP files, examine logs for the specific AJAX action, and remove unknown administrator accounts. If a compromise is confirmed, restoring from a clean backup is the recommended course of action.Source: Bleeping Computer
Vulnerability Management
Hackers exploit critical WooCommerce plugin vulnerability
(Credit: Bilal Ulker – stock.adobe.com)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
