CVE Tools

CVE-2026-27540

WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability

Published: Mar 19, 2026Updated: Apr 29, 2026 Sources: CVE List NVDCWE-434

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

In plain language

AI Act now

This WordPress plugin flaw lets anyone on the internet upload malicious files to your site without logging in, and it’s already being exploited—small businesses running it should act immediately.

Executive summary

CVE-2026-27540 is an unauthenticated arbitrary file upload (CWE-434) in the WordPress Woocommerce Wholesale Lead Capture plugin via the wwlc_file_upload_handler AJAX action, enabling attackers to upload PHP web shells for remote code execution; exploitation has been reported in the wild (spiking in multiple periods in 2026).

If affected, business impact
Website/server takeoverMalicious backdoor installationCustomer/business data theftSite downtime or ransomware risk

What to do now

  1. Check whether you run the “Woocommerce Wholesale Lead Capture” WordPress plugin and confirm its version is 2.0.3.1 or earlier (via WordPress Admin → Plugins).
  2. If it’s installed and version is ≤ 2.0.3.1, temporarily remove/disable the plugin immediately to stop uploads.
  3. Apply the vendor’s fix for CVE-2026-27540 as soon as a fixed version is available; in the provided findings, no specific fixed version is listed, so verify the latest patch release with the plugin author and upgrade promptly.
  4. If you can’t patch immediately, block direct access to the plugin’s upload/handler endpoints at your web server/WAF level (or deny requests to the wwlc_file_upload_handler action) and monitor for new PHP files/web shells in the WordPress folders.
Some work to apply

CVSS Vector Breakdown

AV:NAC:HPR:NUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

3 techniques
Command and Control
Initial Access
Persistence
View detailed technique mapping

References

2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-27540 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows