Key Facts
Wordfence reports active exploitation of CVE-2026-27540 in the WooCommerce Wholesale Lead Capture premium plugin. The issue affects versions 2.0.3.1 and earlier.
Technical Details
BleepingComputer’s reporting describes CVE-2026-27540 as an unauthenticated arbitrary file-upload flaw that attackers use to upload PHP backdoors. Wordfence documented more than 100,000 blocked attacks.
Impact & Mitigation
Update to version 2.0.3.2 or later. Review upload directories for unexpected PHP files, inspect requests to admin-ajax.php invoking wwlc_file_upload_handler, and investigate potentially compromised sites.
