CVE-2026-27540
CRITICAL · 9.0 EPSS 1.7%active exploitation confirmed by Wordfence; patch released; no KEV yet but strong defender signal.
What: Unrestricted file upload vulnerability in WooCommerce Wholesale Lead Capture plugin (≤2.0.3.1) allows unauthenticated PHP webshell uploads on WordPress sites. CVSS 9.0 CRITICAL.
Why it matters: Wordfence reports 100k+ active exploitation attempts blocked; patch released (v2.0.3.2); mass scanning and PHP backdoor deployment observed in the wild. Not yet KEV-listed but defender triage and vendor patching underway confirm real-world weaponization.
Where it's seen: Security vendor (Wordfence) telemetry, urgent patch advisories, multi-language social amplification calling for immediate updates, practitioner warning threads.
RISK: CRITICAL — unauthenticated RCE via file upload; mass exploitation; 100k+ attacks documented.
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- High
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High