WooCommerce Wholesale Lead Capture Vulnerability Exploited to Take Over WordPress Websites

Views: 53 views

510/69 Wednesday, September 16, 2026

Wordfence disclosed that attackers have been exploiting CVE-2026-27540, a Critical vulnerability with a CVSS score of 9.8 in the WooCommerce Wholesale Lead Capture plugin for WordPress. The vulnerability affects version 2.0.3.1 and earlier. It allows unauthenticated attackers to upload PHP files to websites, potentially leading to command execution on the server. Wordfence stated that it has blocked more than 100,000 exploitation attempts and observed attack activity continuing for several months.

The vulnerability stems from the plugin’s file upload function being accessible without authentication, combined with improper file type validation. This allows attackers to define file types permitted by the system and upload malicious PHP files to the website. If exploitation succeeds, the attacker can execute the uploaded file to run commands on the server, potentially leading to website takeover. The observed attacks involved uploading PHP web shells capable of collecting system information and serving as a channel for uploading additional files.

The vulnerability has been fixed in WooCommerce Wholesale Lead Capture version 2.0.3.2. Website administrators using the plugin should update to version 2.0.3.2 or later. They should also inspect their websites for unknown or recently created PHP files, as well as unusual administrator accounts and suspicious activity. If there is evidence that a website has been compromised, administrators should assess the scope of impact and look for backdoors or persistence mechanisms that attackers may have used to maintain access to the system.

Source: https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin