CVE-2026-27542 is an incorrect privilege assignment vulnerability in Rymera Web Co Pty Ltd.'s WooCommerce Wholesale Lead Capture WordPress plugin. The flaw affects versions through 2.0.3.1 and allows privilege escalation. Available information indicates that the plugin improperly assigns privileges, enabling an attacker to obtain permissions beyond those intended by the application. Specific vulnerable code paths or functions have not been disclosed in the available information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python exploit script, a README, and a license file. The Python script is an interactive multi-target exploitation tool for two WordPress plugin vulnerabilities in WooCommerce Wholesale Lead Capture (WWLC): CVE-2026-27540 (unauthenticated arbitrary file upload leading to RCE) and CVE-2026-27542 (unauthenticated privilege escalation via registration role injection). The script uses requests with disabled TLS verification, multithreading via ThreadPoolExecutor, and an interactive CLI with two modes. Mode 1 uploads a PHP shell and then brute-forces the dynamically generated wwlc-temp-* folder beneath /wp-content/uploads to locate the uploaded file. Mode 2 submits crafted registration data to create a new user with administrator capabilities, then checks for admin access. The code appears operational rather than a simple detector: it performs exploitation, supports bulk target processing, writes results to local files, and includes hardcoded credentials/password defaults for the registration path. The README documents the intended vulnerable AJAX actions (wwlc_file_upload_handler and wwlc_create_user), the target endpoint (/wp-admin/admin-ajax.php), and the expected post-exploitation outcomes.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
A privilege escalation vulnerability caused by incorrect privilege assignment in the WooCommerce Wholesale Lead Capture plugin.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.