Report
Critical WooCommerce plugin flaw exploited to upload PHP backdoors
A critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress is being actively exploited to upload PHP backdoors. The flaw affects plugin versions 2.0.3.1 and older, and a fixed version is available.
A critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress is being actively exploited, according to BleepingComputer. The flaw, tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vulnerability discovered by security researcher Teemu Saarentaus. Attackers can upload PHP webshells and execute code, potentially leading to complete site compromise.
The technical cause is an exposed unauthenticated AJAX action named wwlc_file_upload_handler. That action checks file extensions against an allowlist supplied through the user-controlled file_settings request parameter. This allows an attacker to add ‘php’ to permitted file types, so the plugin accepts PHP executable file uploads. The vulnerability was addressed in version 2.0.3.2, released on February 20.
Wordfence, a WordPress security company, blocked over 100,000 attacks linked to CVE-2026-27540. Exploitation activity spiked between June 4 and June 17, and on July 1 and August 30. During attacks, hackers upload a webshell that conducts reconnaissance but can also introduce additional payloads. The uploaded shell.php reports host details and provides a browser-based upload form for writing additional malicious files to the site.
Administrators are recommended to add high-offender IP addresses provided by Wordfence to a blocklist and upgrade to plugin version 2.0.3.2 or later. Researchers advise checking upload directories for unexpected or recently created PHP files, examining logs for requests to /wp-admin/admin-ajax.php invoking wwlc_file_upload_handler, and removing unknown administrator accounts. If compromise is confirmed, the recommended action is to restore the website from a safe backup, as removing all persistence mechanisms, users, and backdoors may be complicated.
Our reading
Our reading is that any site running the affected plugin versions should treat the upgrade and the listed detection steps as urgent, because the flaw is unauthenticated and exploitation is already widespread.
Source details and supporting facts
Each line is stated by the page named above it.
Stated by BleepingComputer
- Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.
- The flaw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older.
- It is an unauthenticated arbitrary file-upload vulnerability discovered by security researcher Teemu Saarentaus.
- The vulnerability was addressed in version 2.0.3.2 of the WooCommerce Wholesale Lead Capture plugin, released on February 20.
- Wordfence blocked over 100,000 attacks linked to CVE-2026-27540.
- Exploitation activity spiked between June 4 and June 17, and on July 1 and August 30.
- Administrators are recommended to add them to a blocklist and upgrade to plugin version 2.0.3.2 or later that addresses the security problem.
- If compromise is confirmed, the recommended action is to restore the website from a safe backup, as removing all persistence mechanisms, users, and backdoors may be complicated.
Sources
- BleepingComputerText stored 15 September 2026
How this story was checked. Written from the 1 page listed above, stored 15 September 2026; claims checked against that stored text on 15 September 2026.
What that means
- 8 of 8 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
- Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
- The check reads stored text only: no claim rests on a fresh look that did not happen.
- Where the reporting was silent, the text says so instead of filling the gap.
More from Security
Report
Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warning
Brief
Google releases September 2026 patches for Pixel, fixing actively exploited zero-day
Brief