Attackers are actively exploiting CVE-2026-27540, a critical CVSS 9.8 unauthenticated arbitrary-file-upload flaw in the WordPress/WooCommerce Wholesale Lead Capture plugin. Versions through 2.0.3.1 trust attacker-controlled file-type settings in the public wholesale-registration form, allowing attackers to upload executable PHP files without logging in and gain remote code execution on the hosting server.
Exploitation has reportedly persisted for months, and Wordfence has blocked more than 100,000 attempts against roughly 6,000 active installations. Affected operators should upgrade to version 2.0.3.2 and investigate for PHP webshells, unauthorized administrator accounts, altered checkout content, persistence mechanisms, suspicious outbound connections, and related log activity.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
Wordfence made the CVE-2026-27540 firewall rule available to users of its free version.
Wordfence Premium, Care, and Response users received a firewall rule for known CVE-2026-27540 exploitation.
Wordfence reported active exploitation of CVE-2026-27540 for months and said its firewall had blocked more than 100,000 attempts. Observed requests invoked the unauthenticated wwlc_file_upload_handler AJAX action to upload PHP webshells such as shell.php.
Wordfence observed an additional notable exploitation burst targeting the vulnerable upload handler on August 30.
Wordfence recorded another notable burst of exploit attempts against CVE-2026-27540 on July 1.
Wordfence observed elevated blocked exploitation activity targeting the vulnerable WooCommerce plugin between June 4 and June 17.
CVE-2026-27540 was disclosed as a critical unauthenticated arbitrary file-upload flaw in Wholesale Lead Capture Plugin for WooCommerce versions 2.0.3.1 and earlier. Version 2.0.3.2 remediates the issue, which can allow PHP webshell uploads through the public wholesale-registration upload handler.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.