Key Facts

Wordfence reports active exploitation of CVE-2026-27540 in the WooCommerce Wholesale Lead Capture premium plugin. The issue affects versions 2.0.3.1 and earlier.

Technical Details

BleepingComputer’s reporting describes CVE-2026-27540 as an unauthenticated arbitrary file-upload flaw that attackers use to upload PHP backdoors. Wordfence documented more than 100,000 blocked attacks.

Impact & Mitigation

Update to version 2.0.3.2 or later. Review upload directories for unexpected PHP files, inspect requests to admin-ajax.php invoking wwlc_file_upload_handler, and investigate potentially compromised sites.

Sources

By Allan