Vulnerability
Published 2026-09-15
Verified 2026-09-19

WooCommerce Wholesale Lead Capture: unauth file upload to PHP webshell (CVE-2026-27540); actively exploited

BleepingComputer (15 September 2026) relays Wordfence/Defiant telemetry that attackers are actively exploiting CVE-2026-27540 in the premium WooCommerce Wholesale Lead Capture WordPress plugin. Unauthenticated AJAX action wwlc_file_upload_handler accepts a user-controlled file_settings allowlist, letting attackers permit .php uploads and drop webshells (researcher: Teemu Saarentaus). Affected: versions 2.0.3.1 and older; fixed in 2.0.3.2 (released 20 February). Wordfence reports 100,000+ blocked attacks with spikes around 4–17 June, 1 July, and 30 August 2026; The Hacker News (16 September) cites CVSS 9.8 and lists recent attacker IPs (including 92.241.13.213, 31.59.129.150, 92.241.13.140, 23.137.105.214, 23.180.120.140, 104.194.9.138, 187.75.114.36, 114.10.43.203, 37.114.144.209 and IPv6 2a0f:85c1:840:5389::1). Hunt admin-ajax.php calls to wwlc_file_upload_handler, unexpected PHP under uploads (e.g. shell.php), and unknown admin accounts; upgrade to 2.0.3.2+. Primary wire: BleepingComputer; UPDATE 17 Sep: CVSS + IoCs from THN/Wordfence.

Product
WooCommerce Wholesale Lead Capture (WordPress premium plugin)
Versions
≤ 2.0.3.1 affected; fixed 2.0.3.2 (20 Feb release per wire)
CVSS
9.8
Exploited in Australia?
unknown
Patch to
Upgrade WooCommerce Wholesale Lead Capture to 2.0.3.2 or later; block Wordfence-listed attacker IPs; audit uploads and admin-ajax wwlc_file_upload_handler hits

Primary: BleepingComputer — WooCommerce Wholesale Lead Capture CVE-2026-27540 (15 Sep 2026) · CVE: CVE-2026-27540 · The Hacker News — WooCommerce Wholesale webshells / CVSS 9.8 (16 Sep 2026)

vulnerabilities cloud