Security Advisory: Exploitation of WooCommerce Plugin Vulnerability (CVE‑2026‑27540)
- Defiant issues warning regarding exploitation of a flaw in the WooCommerce Wholesale Lead Capture Plugin
- Critical unauthenticated file-upload vulnerability allows attackers to deploy PHP web shells for total site compromise
- Patch released in February 2026 (v2.0.3.2); Wordfence thwarted over 100,000 attacks, users are urged to upgrade and review uploads
A significant vulnerability has been identified within the widely used WooCommerce plugin, raising alarms as it is actively exploited to implant malware and possibly take control of entire websites, according to cybersecurity professionals.
The implicated plugin, known as the Wholesale Lead Capture Plugin for WooCommerce, is designed to facilitate a dedicated registration and onboarding process tailored for wholesale and B2B clients.
This functionality enables businesses to gather company-specific data, assess applications, allocate wholesale user roles, and automate essential registration and onboarding communications.
This premium plugin, priced between $99 and $600, boasts over 20,000 active installations as indicated on its WordPress store page.
Prevalence of Victims
The vulnerability allows for an unauthenticated arbitrary file-upload exploit, permitting unauthorized actors to upload a variety of files, including PHP web shells and executable code, which can lead to an entire site takeover. This flaw is cataloged as CVE-2026-27540 and is rated with a critical severity score of 9.0 out of 10.
Versions 2.0.3.1 and earlier are reportedly susceptible. The corrective version, 2.0.3.2, was unveiled on February 20 and has been available for several months.
Notably, the cybersecurity firm Defiant reported that its Wordfence web application firewall successfully impeded more than 100,000 attacks, including two notable spikes in activity – the first occurring between June 4 and June 17, and another from July 1 to August 30.

During these attack attempts, assailants primarily deployed reconnaissance web shells, potentially mapping the affected sites prior to unleashing more damaging malware.
“The uploaded shell.php functions as a PHP web shell that divulges host details while providing a browser-based interface for further malicious file uploads,” the researchers remarked.
If affected by this plugin, it is strongly recommended that users promptly update to the latest version and scrutinize any upload directories for unfamiliar or newly created PHP files.
Source link: Techradar.com.




