{
  "id": 8455663,
  "title": "Webshell campaign exploits critical WooCommerce plugin flaw",
  "url": "https://urgent.news/2026/09/19/webshell-campaign-exploits-critical-woocommerce-plugin-flaw",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-19T11:59:23.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/webshell-campaign-exploits-critical-woocommerce-plugin-flaw-2/"
  },
  "original_language": "en",
  "account": "Attackers are targeting a critical flaw in the WooCommerce Wholesale Lead Capture plugin, uploading malicious PHP webshells onto vulnerable WordPress sites. Since June, over 100,000 exploit attempts have been thwarted by Wordfence's firewall. The vulnerability, CVE-2026-27540, was patched in version 2.0.3.2 on February 20 but remains a threat due to unpatched sites. The flaw allows unauthenticated attackers to upload arbitrary files, exploiting a design oversight in the plugin's upload routine. Wordfence categorizes the bug as highly critical, with a CVSS severity score of 9.8, while Patchstack rates it at 9.0. The attack primarily occurred between June and August, with another spike on July 1 and August 30. Attackers plant a PHP file named shell.php, providing unauthorized access for reconnaissance, installing further malicious code, and altering website content. The vulnerability exists in an AJAX action, wwlcfileupload_handler, processing files from the plugin's wholesale registration functionality. The plugin, developed by Rymera Web Co Pty Ltd, is used for managing wholesale customer registration and onboarding. Despite the patch, sites remain at risk if they haven't updated, highlighting the importance of timely software updates and diligent site maintenance.",
  "summary": "Attackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP webshells onto WordPress sites, with more than 100,000 exploit attempts blocked since June, Wordfence data shows. The flaw, tracked as CVE-2026-27540, affects versions 2.0.3.1 and earlier of the premium plugin and allows unauthenticated attackers to upload arbitrary files to a…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Arabian Post",
        "title": "Webshell campaign exploits critical WooCommerce plugin flaw",
        "url": "https://urgent.news/2026/09/19/webshell-campaign-exploits-critical-woocommerce-plugin-flaw-8455664",
        "published": "2026-09-19T11:59:23.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}