Urgent.News

What's breaking now, across thousands of outlets.

Tech

Webshell campaign exploits critical WooCommerce plugin flaw

Attackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP webshells onto WordPress sites, with more than 100,000 exploit attempts blocked since June, Wordfence data shows. The flaw, tracked as CVE-2026-27540, affects versions 2.0.3.1 and earlier of the premium plugin and allows unauthenticated attackers to upload arbitrary files to a…

Attackers are actively targeting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin, exploiting it to upload PHP webshells onto WordPress sites. Since June, more than 100,000 attempts to exploit CVE-2026-27540 have been blocked, according to Wordfence data. The flaw, affecting versions 2.0.3.1 and earlier, allows unauthenticated attackers to upload arbitrary files to vulnerable servers.

Wordfence rates the bug 9.8 on the CVSS severity scale, while Patchstack's CVE record gives it a 9.0 score. The scoring difference is due to differing assessments of attack complexity, with Wordfence considering it low complexity and Patchstack rating it as high. Successful exploitation can lead to remote code execution and full compromise of an affected website.

Security researchers have observed attackers using the flaw to plant a file named shell.php, which provides attackers with a foothold for further malicious activity. The vulnerability exists in an AJAX action that processes files submitted through the plugin's wholesale registration functionality. The issue was disclosed on February 20 and patched on February 20, with Wordfence introducing a firewall rule on February 27 and adding support for the free service on March 29.

Despite the patch, some sites remain vulnerable due to outdated plugin versions. Administrators are advised to update to version 2.0.3.2 or later and inspect their servers for malicious files.

Written by urgent.news from Arabian Post's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at thearabianpost.com →

More in Tech

What I Will Not Port While the Rails Move

GitHub: https://github.com/abrownfox0/abrownfox001-twap60-prediction-trigger-system YouTube walkthrough: https://www.youtube.com/watch?v=XzhugRL6BV4 Live profile: https://polymarket.com/@abrownfox001…

More from Saturday 19 September →