CVE-2026-27540
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.
In plain language
AI Act nowThis WordPress plugin flaw lets anyone on the internet upload malicious files to your site without logging in, and it’s already being exploited—small businesses running it should act immediately.
CVE-2026-27540 is an unauthenticated arbitrary file upload (CWE-434) in the WordPress Woocommerce Wholesale Lead Capture plugin via the wwlc_file_upload_handler AJAX action, enabling attackers to upload PHP web shells for remote code execution; exploitation has been reported in the wild (spiking in multiple periods in 2026).
What to do now
- Check whether you run the “Woocommerce Wholesale Lead Capture” WordPress plugin and confirm its version is 2.0.3.1 or earlier (via WordPress Admin → Plugins).
- If it’s installed and version is ≤ 2.0.3.1, temporarily remove/disable the plugin immediately to stop uploads.
- Apply the vendor’s fix for CVE-2026-27540 as soon as a fixed version is available; in the provided findings, no specific fixed version is listed, so verify the latest patch release with the plugin author and upgrade promptly.
- If you can’t patch immediately, block direct access to the plugin’s upload/handler endpoints at your web server/WAF level (or deny requests to the wwlc_file_upload_handler action) and monitor for new PHP files/web shells in the WordPress folders.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-27540 and every CVE in our database. Create a free account — no credit card required.
Create Free Account