SOCRadar®[verified]@socradarActive Exploitation
CVE-2026-27540 affects the WooCommerce Wholesale Lead Capture plugin via unauthenticated arbitrary file upload leading to RCE (CVSS 9.8), and is being actively exploited in the wild with over 100,000 blocked attempts reported by Wordfence. Updating to version 2.0.3.2+ is recommended as remediation.
Threat Landscape[verified]@LandscapeThreatActive Exploitation
The post reports active exploitation of WordPress plugin vulnerabilities to upload PHP web shells and achieve unauthenticated RCE, and advises patching affected plugins while inspecting suspicious requests and uploads.
DEGEN 👑[verified]@iamjustapeActive Exploitation
The text reports that CVE-2026-27540 affecting WooCommerce Wholesale Lead Capture was patched in February but is currently under active exploitation with over 100,000 blocked attempts per Wordfence, indicating ongoing attacks despite the patch.
DEGEN 👑[verified]@iamjustapeActive Exploitation
The post alerts that CVE-2026-27540 in WooCommerce Wholesale Lead Capture, despite being patched in February, is currently under active exploitation with over 100,000 blocked attempts reported by Wordfence, urging immediate version checks.
Venkata Satish Guttula 🛰️[verified]@snakeyesV1Active Exploitation
Critical unauthenticated PHP webshell upload (CVSS 9.8) in WooCommerce Wholesale Lead Capture is being actively exploited, with 100k+ blocked attempts reported; users should update to v2.0.3.2+ and scan uploads.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE‑2026‑27540 is a CVSS 9.8 unauthenticated file‑upload flaw in a WooCommerce plugin that is currently being actively exploited, with over 100k blocked attempts recorded. The tweet advises hunting admin‑ajax.php logs and checking upload directories for PHP files to detect the activity.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The text reports active, ongoing exploitation of CVE-2026-27540 (CVSS 9.8) in WooCommerce Wholesale Lead Capture, with over 100,000 blocked attempts and campaigns persisting months after the February 2026 patch (v2.0.3.2). It includes detailed technical analysis of the unauthenticated file upload flaw and hunting guidance.
Frontiera Tech[verified]@FrontieraTechITActive Exploitation
The bulletin emphasizes multiple CVEs being actively exploited, including targeted attacks, CISA KEV inclusion, ransomware exploitation, live attacks, and large-scale abuse attempts. It also provides patch/update guidance, but active exploitation is the dominant theme.