WooCommerce Plugin Exploits Recently Fixed PHP Vulnerability to Install Backdoor on WordPress Sites

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Security Advisory: Exploitation of WooCommerce Plugin Vulnerability (CVE‑2026‑27540)

  • Defiant issues warning regarding exploitation of a flaw in the WooCommerce Wholesale Lead Capture Plugin
  • Critical unauthenticated file-upload vulnerability allows attackers to deploy PHP web shells for total site compromise
  • Patch released in February 2026 (v2.0.3.2); Wordfence thwarted over 100,000 attacks, users are urged to upgrade and review uploads

A significant vulnerability has been identified within the widely used WooCommerce plugin, raising alarms as it is actively exploited to implant malware and possibly take control of entire websites, according to cybersecurity professionals.

The implicated plugin, known as the Wholesale Lead Capture Plugin for WooCommerce, is designed to facilitate a dedicated registration and onboarding process tailored for wholesale and B2B clients.

This functionality enables businesses to gather company-specific data, assess applications, allocate wholesale user roles, and automate essential registration and onboarding communications.

This premium plugin, priced between $99 and $600, boasts over 20,000 active installations as indicated on its WordPress store page.

Prevalence of Victims

The vulnerability allows for an unauthenticated arbitrary file-upload exploit, permitting unauthorized actors to upload a variety of files, including PHP web shells and executable code, which can lead to an entire site takeover. This flaw is cataloged as CVE-2026-27540 and is rated with a critical severity score of 9.0 out of 10.

Versions 2.0.3.1 and earlier are reportedly susceptible. The corrective version, 2.0.3.2, was unveiled on February 20 and has been available for several months.

Notably, the cybersecurity firm Defiant reported that its Wordfence web application firewall successfully impeded more than 100,000 attacks, including two notable spikes in activity – the first occurring between June 4 and June 17, and another from July 1 to August 30.

A computer monitor displaying the Wordfence security dashboard sits on a desk in a server room, with a keyboard and coffee cup nearby.

During these attack attempts, assailants primarily deployed reconnaissance web shells, potentially mapping the affected sites prior to unleashing more damaging malware.

“The uploaded shell.php functions as a PHP web shell that divulges host details while providing a browser-based interface for further malicious file uploads,” the researchers remarked.

If affected by this plugin, it is strongly recommended that users promptly update to the latest version and scrutinize any upload directories for unfamiliar or newly created PHP files.

Source link: Techradar.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading