Webshell campaign exploits critical WooCommerce plugin flaw
Attackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP webshells onto WordPress sites, with more than 100,000 exploit attempts blocked since June, Wordfence data shows. The flaw, tracked as CVE-2026-27540, affects versions 2.0.3.1 and earlier of the premium plugin and allows unauthenticated attackers to upload arbitrary files to a…
Attackers are targeting a critical flaw in the WooCommerce Wholesale Lead Capture plugin, uploading malicious PHP webshells onto vulnerable WordPress sites. Since June, over 100,000 exploit attempts have been thwarted by Wordfence's firewall. The vulnerability, CVE-2026-27540, was patched in version 2.0.3.2 on February 20 but remains a threat due to unpatched sites.
The flaw allows unauthenticated attackers to upload arbitrary files, exploiting a design oversight in the plugin's upload routine. Wordfence categorizes the bug as highly critical, with a CVSS severity score of 9.8, while Patchstack rates it at 9.0. The attack primarily occurred between June and August, with another spike on July 1 and August 30.
Attackers plant a PHP file named shell.php, providing unauthorized access for reconnaissance, installing further malicious code, and altering website content. The vulnerability exists in an AJAX action, wwlcfileupload_handler, processing files from the plugin's wholesale registration functionality. The plugin, developed by Rymera Web Co Pty Ltd, is used for managing wholesale customer registration and onboarding.
Despite the patch, sites remain at risk if they haven't updated, highlighting the importance of timely software updates and diligent site maintenance.
Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
Also reported by 1 other outlet
- Webshell campaign exploits critical WooCommerce plugin flaw thearabianpost.com