← back

CVE-2026-27540

CRITICAL · 9.0 EPSS 1.7%
hype LIKELY HACK · 78 hack

active exploitation confirmed by Wordfence; patch released; no KEV yet but strong defender signal.

What: Unrestricted file upload vulnerability in WooCommerce Wholesale Lead Capture plugin (≤2.0.3.1) allows unauthenticated PHP webshell uploads on WordPress sites. CVSS 9.0 CRITICAL.

Why it matters: Wordfence reports 100k+ active exploitation attempts blocked; patch released (v2.0.3.2); mass scanning and PHP backdoor deployment observed in the wild. Not yet KEV-listed but defender triage and vendor patching underway confirm real-world weaponization.

Where it's seen: Security vendor (Wordfence) telemetry, urgent patch advisories, multi-language social amplification calling for immediate updates, practitioner warning threads.

RISK: CRITICAL — unauthenticated RCE via file upload; mass exploitation; 100k+ attacks documented.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/15/2026, 6:23:08 PM

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

CVSS 3.1 breakdown

Exploitability 2.2 · Impact 6.0
vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Complexity
High
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Weaknesses