Cybersecurity

Active Exploitation of a Critical Vulnerability in WooCommerce Plugin Threatens WordPress Sites

Attackers are exploiting an undocumented critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload malicious PHP files and potentially take control of WordPress sites. Wordfence has blocked more than 100,000 attacks, while administrators should update to version 2.0.3.2 or later and check for signs of compromise.

2026-09-15
3 min read
6 views
فريق تحرير certi.news
Active Exploitation of a Critical Vulnerability in WooCommerce Plugin Threatens WordPress Sites
Attackers are exploiting an undocumented critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload malicious PHP files and potentially take control of WordPress sites. Wordfence has blocked more than 100,000 attacks, while administrators should update to version 2.0.3.2 or later and check for signs of compromise.

Attackers are exploiting a critical security vulnerability in the paid WooCommerce Wholesale Lead Capture plugin for WordPress sites to upload malicious PHP files that can be used to execute commands and gain full control of the site. The vulnerability is tracked as CVE-2026-27540 and affects version 2.0.3.1 and earlier versions.

Security researcher Teemu Saarentaus discovered the vulnerability, which was classified as an unauthenticated arbitrary file upload vulnerability. The company fixed the issue in version 2.0.3.2, released on February 20, so updating to this version or later is the essential action for sites using the plugin.

How Does the Exploitation Occur?

The issue is related to an unauthenticated, exposed AJAX action named wwlc_file_upload_handler. The action checks file extensions based on an allowlist supplied by the user in the file_settings parameter. Because an attacker can manipulate this parameter and add the php extension to it, they can submit an executable PHP file to the site.

According to Wordfence, the attacker sends a forged request to the action with a malicious file bearing the PHP extension. This results in the upload of a web shell, such as shell.php, which can gather information about the host and provide a browser-based form for uploading additional files to the site. This means the exploitation is not limited to inserting an unwanted file, but may enable the installation of an additional payload and the maintenance of access to the server.

Indicators of a Broad Exploitation Campaign

Defiant, the owner of the Wordfence service, warned of active exploitation of the vulnerability. It said that the Wordfence firewall blocked more than 100,000 attacks associated with CVE-2026-27540. Activity increased particularly between June 4 and 17, followed by additional waves on July 1 and August 30.

Wordfence also provided a list of highly active IP addresses that it said carried out tens of thousands of exploitation attempts, and recommended that site administrators add them to blocklists alongside installing the patched version.

What Should Site Administrators Do?

  • Update the WooCommerce Wholesale Lead Capture plugin to version 2.0.3.2 or later.
  • Scan upload directories for unexpected or recently created PHP files.
  • Review logs for requests to the /wp-admin/admin-ajax.php path that invoke the wwlc_file_upload_handler action.
  • Check for unknown administrator accounts and delete them when discovered.

If a compromise is confirmed, the researchers’ guidance recommends restoring the site from a secure backup. This is important because it is difficult to ensure the manual removal of all persistence mechanisms, accounts, and malicious backdoor files. This incident demonstrates that third-party plugins, even when operating within an e-commerce store built on WordPress, may give an attacker a direct entry point to the site if they are not updated in a timely manner.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news