Exploited in the wild WooCommerce Wholesale Lead Capture rce The Events Calendar WooCommerce web-app
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
CVE Tools coverage
Attackers are actively exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture, affecting all versions up to and including 2.0.3.1. The missing file-type validation lets unauthenticated attackers upload PHP web shells, enabling remote code execution and further compromise of WordPress sites. Separately, The Events Calendar is affected by CVE-2026-78159 in versions <= 6.17.3 and CVE-2026-78006 in versions <= 6.17.4; both can lead to unauthenticated remote code execution when event comments are enabled. StellarWP fixed these issues in versions 6.17.3.1 and 6.17.4.1, while WooCommerce Wholesale Lead Capture users should investigate unexpected PHP files and suspicious wwlc_file_upload_handler requests.