CVE Tools
Back to feed
Exploited in the wild WordPress web-app WooCommerce Wholesale Lead Capture AutoPlugins LLC rce

Hackers target WordPress sites via third-party WooCommerce plugin

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Attackers are actively exploiting CVE-2026-27540 in AutoPlugins LLC's WooCommerce Wholesale Lead Capture for WordPress versions 2.0.3.1 and older. The unauthenticated file-upload flaw lets attackers upload PHP webshells, execute code, and potentially take over affected WordPress sites; administrators should upgrade to version 2.0.3.2 or later and investigate unexpected PHP uploads and related AJAX requests.