Hackers target WordPress sites via third-party WooCommerce plugin
A critical vulnerability CVE-2026-27540 in the premium WooCommerce Wholesale Lead Capture plugin (versions 2.0.3.1 and older) allows unauthenticated PHP backdoor uploads. Wordfence blocked over 100,000 attacks; a fix was released in version 2.0.3.2 on 20 February.
- CVE-2026-27540 — unauthenticated arbitrary file upload via AJAX action wwlc_file_upload_handler
- Wordfence blocked over 100,000 attacks, peak exploitation 4–17 June
- Vulnerability fixed in version 2.0.3.2, released 20 February
- Attackers upload shell.php for reconnaissance and further malware
Read next
Security