CVE-2026-27540Active Exploitation

HIGHCVSS 9.0 · CRITICAL

Exploitation observed; activity peaked at 18 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 33 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 41 mentions across 11 observed days

What's happening

  • Active exploitation reported across 33 signals
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 23 signals
  • Technical details provided in 33 signals
  • Disclosure: 4 classified signals
  • Peaked 6d ago at 18 mentions (2026-09-16); latest day: 1
  • 41 total mentions across 11 days

Deep dive

Activity timeline41 mentions / 11d
0591418Mentions · 2026-02-25: 1Mentions · 2026-03-19: 4Mentions · 2026-09-14: 1Mentions · 2026-09-15: 7Mentions · 2026-09-16: 18Mentions · 2026-09-17: 4Mentions · 2026-09-18: 1Mentions · 2026-09-19: 1Mentions · 2026-09-23: 2Mentions · 2026-09-24: 1Mentions · 2026-10-03: 1PoC Mentioned / Linked · 2026-02-25: 1Exploit Tool / Code · 2026-02-25: 1Exploit Tool / Code · 2026-09-15: 1Exploit Tool / Code · 2026-09-16: 2Exploit Tool / Code · 2026-09-18: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-03-19: 1Active Exploitation · 2026-09-14: 1Active Exploitation · 2026-09-15: 6Active Exploitation · 2026-09-16: 17Active Exploitation · 2026-09-17: 2Active Exploitation · 2026-09-18: 1Active Exploitation · 2026-09-19: 1Active Exploitation · 2026-09-23: 2Active Exploitation · 2026-09-24: 1Patch / Workaround · 2026-09-14: 1Patch / Workaround · 2026-09-15: 4Patch / Workaround · 2026-09-16: 12Patch / Workaround · 2026-09-17: 2Patch / Workaround · 2026-09-19: 1Patch / Workaround · 2026-09-23: 2Patch / Workaround · 2026-09-24: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-19: 4Technical Details · 2026-09-14: 1Technical Details · 2026-09-15: 7Technical Details · 2026-09-16: 15Technical Details · 2026-09-17: 2Technical Details · 2026-09-18: 1Technical Details · 2026-09-19: 1Technical Details · 2026-09-24: 102-2503-1909-1409-1509-1609-1709-1809-1909-2309-2410-03
Signal classification4 categories
Active Exploitation
3280.0%
Disclosure
410.0%
Patch
37.5%
Exploit
12.5%
Referenced assets25 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-251
Exploit1
2026-03-194
Active Exploitation1Disclosure3
2026-09-141
Active Exploitation1
2026-09-157
Active Exploitation6Patch1
2026-09-1618
Active Exploitation17Patch1
2026-09-174
Active Exploitation2Disclosure1Patch1
2026-09-181
Active Exploitation1
2026-09-191
Active Exploitation1
2026-09-232
Active Exploitation2
2026-09-241
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Active Exploitation

    🚨 Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells. Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1. Read: https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html

    Post summary

    The text reports that CVE-2026-27540 in WooCommerce Wholesale Lead Capture is being actively exploited by attackers to plant PHP web shells, with Wordfence blocking over 100,000 exploit attempts since June 2026.

    53001062232.8K
    2.4M followersView on X
  • SOCRadar®@socradar
    Active Exploitation

    CVE-2026-27540 is being actively exploited against the WooCommerce Wholesale Lead Capture plugin for WordPress. → CVSS 9.8 → Unauthenticated arbitrary file upload, leads to RCE → Affects 2.0.3.1 and earlier → Wordfence: 100,000+ blocked exploitation attempts Update to 2.0.3.2+. Check for suspicious PHP uploads, unfamiliar admin accounts, and modified files. Read more: https://hubs.la/Q04xDYDN0 #CyberSecurity #WordPress #RCE #WooCommerce

    Post summary

    CVE-2026-27540 affects the WooCommerce Wholesale Lead Capture plugin via unauthenticated arbitrary file upload leading to RCE (CVSS 9.8), and is being actively exploited in the wild with over 100,000 blocked attempts reported by Wordfence. Updating to version 2.0.3.2+ is recommended as remediation.

    00031595
    7.1K followersView on X
  • Threat Landscape@LandscapeThreat
    Active Exploitation

    Threat actors are exploiting critical WordPress plugin vulnerabilities to upload PHP web shells and achieve unauthenticated remote code execution. - WooCommerce Wholesale Lead Capture CVE-2026-27540 enables arbitrary file uploads through the wwlc_file_upload_handler AJAX action; more than 100,000 exploit attempts have been blocked since June 2026. - Observed shell.php payloads report host details and provide a browser-based mechanism to upload additional files. - Two The Events Calendar flaws, CVE-2026-78159 and CVE-2026-78006, enable remote code execution through pending-comment previews and can result in administrator password reset, malicious plugin upload, data theft, or full site takeover. - Site owners should patch affected plugins and inspect uploads directories and suspicious admin-ajax.php requests. VULNERABILITY CVE-2026-27540 CVE-2026-78006 CVE-2026-78159 INDICATOR 104.194.9.138 114.10.43.203 187.75.114.36 23.137.105.214 23.180.120.140 31.59.129.150 37.114.144.209 92.241.13.140 92.241.13.213 ipv6:2a0f:85c1:840:5389::1 Get free accont on threatlandscape io

    Post summary

    The post reports active exploitation of WordPress plugin vulnerabilities to upload PHP web shells and achieve unauthenticated RCE, and advises patching affected plugins while inspecting suspicious requests and uploads.

    0003087
    109 followersView on X
  • DEGEN 👑@iamjustape
    Active Exploitation

    vulnerability was patched in February. It's now under active exploitation right now 100,000+ blocked attempts, per Wordfence, with fresh attempts every single day. CVE-2026-27540, WooCommerce Wholesale Lead Capture. It's old news doesn't mean the ecosystem actually patched it. https://t.co/HquiACTWJG

    Post summary

    The text reports that CVE-2026-27540 affecting WooCommerce Wholesale Lead Capture was patched in February but is currently under active exploitation with over 100,000 blocked attempts per Wordfence, indicating ongoing attacks despite the patch.

    0100069
    4.0K followersView on X
  • DEGEN 👑@iamjustape
    Active Exploitation

    Good morning. This bug was patched in February. It's now under active exploitation, still 100,000+ blocked attempts and counting, per Wordfence's own reporting from 5 days ago. CVE-2026-27540, WooCommerce Wholesale Lead Capture. "It's old news" doesn't mean it's handled. Check your version today.

    Post summary

    The post alerts that CVE-2026-27540 in WooCommerce Wholesale Lead Capture, despite being patched in February, is currently under active exploitation with over 100,000 blocked attempts reported by Wordfence, urging immediate version checks.

    0100084
    4.0K followersView on X
  • Venkata Satish Guttula 🛰️@snakeyesV1
    Active Exploitation

    News: WooCommerce Wholesale Lead Capture CVE-2026-27540 (CVSS 9.8): unauth PHP webshell upload via wwlc_file_upload_handler. Wordfence blocked 100k+ attempts. Update to 2.0.3.2+; scan uploads for .php. https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html

    Post summary

    Critical unauthenticated PHP webshell upload (CVSS 9.8) in WooCommerce Wholesale Lead Capture is being actively exploited, with 100k+ blocked attempts reported; users should update to v2.0.3.2+ and scan uploads.

    0001078
    3.0K followersView on X
  • Phil_Taboada@Phil24275443
    Patch

    Te piden el mayorista y suben un archivo a tu tienda sin que lo sepas. Alguien ya lo usa. Actualiza el plugin de pedidos al por mayor (2.0.3.2+). Si no, pueden entrar sin pedir acceso. https://www.wavys-technologies.com/es/blog/woocommerce-wholesale-lead-capture-cve-2026-27540

    Post summary

    The tweet warns that the WooCommerce Wholesale Order Form plugin vulnerability is being used and urges updating to version 2.0.3.2 or later to prevent unauthorized file upload and access.

    1000043
    3 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-27540, a CVSS 9.8 unauthenticated file-upload flaw in WooCommerce Wholesale Lead Capture, is actively exploited with 100k+ blocked attempts. Hunt admin-ajax.php logs for wwlc_file_upload_handler calls and check upload dirs for PHP files. #DFIR_Radar https://t.co/XMKQ8qsnBz

    Post summary

    CVE‑2026‑27540 is a CVSS 9.8 unauthenticated file‑upload flaw in a WooCommerce plugin that is currently being actively exploited, with over 100k blocked attempts recorded. The tweet advises hunting admin‑ajax.php logs and checking upload directories for PHP files to detect the activity.

    10000162
    1.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-27540 (CVSS 9.8) in WooCommerce Wholesale Lead Capture lets unauthenticated attackers upload PHP webshells, with 100,000+ exploitation attempts blocked and active campaigns running since June. - CVE-2026-27540 affects the wwlc_file_upload_handler AJAX action, reachable with no authentication. The plugin reads the permitted file extension list from the attacker's own request rather than server-side config, so submitting php in a forged settings parameter bypasses the only upload barrier. WordPress's upload function is called with type checking disabled, making the extension allowlist the sole control, and the attacker owns it. - Exploitation is a single unauthenticated POST to admin-ajax.php with the wwlc_file_upload_handler action. Uploaded files are commonly named shell.php and drop a webshell that reports host details and provides a browser-based file-write interface for staging further payloads. All plugin versions through 2.0.3.1 are vulnerable; the patch landed February 20 in 2.0.3.2. - Wordfence blocked 100,000+ attempts with heaviest activity June 4-17, plus spikes July 1 and August 30, meaning active exploitation has continued for months post-patch across an estimated 6,000 active installs. Hunt: grep web server access logs for POST requests to admin-ajax.php containing wwlc_file_upload_handler. Audit the WordPress uploads directory for PHP files, especially recently created ones. Check for unknown administrator accounts. #DFIR_Radar

    Post summary

    The text reports active, ongoing exploitation of CVE-2026-27540 (CVSS 9.8) in WooCommerce Wholesale Lead Capture, with over 100,000 blocked attempts and campaigns persisting months after the February 2026 patch (v2.0.3.2). It includes detailed technical analysis of the unauthenticated file upload flaw and hunting guidance.

    10000173
    1.9K followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ CYBER BULLETIN | 2026/09/16 🚨 1. Google patches an exploited Pixel zero-day September Pixel updates cover 110 flaws, including CVE-2026-58704 — a modem privilege-escalation bug Google says is already used in limited, targeted attacks. Install the 2026-09-05 patch level now if you run a supported Pixel. 2. One crafted email can root a Cisco Secure Email Gateway CVE-2026-76461 (CVSS 9.8) is an unauthenticated SQL-injection issue in email parsing that leads to root command execution. CISA added it to the KEV catalog with a Sept. 17 federal deadline. No workarounds exist — patch immediately. 3. Ransomware gangs now exploit VMware vCenter RCE CISA updated its warning on CVE-2026-59310, a critical unauthenticated directory-traversal flaw patched in July: ransomware operators have joined the attacks. Exposed vCenter remains a high-value target for both persistence and ESXi encryption. 4. WSO2 API Manager JWT bypass is under live attack WatchTowr honeypots caught forged admin JWTs exploiting CVE-2026-5430 (CVSS 9.8). Weak signature checks let attackers skip authentication and take over admin accounts on unpatched API Manager and related WSO2 products. 5. WooCommerce plugin abused to drop PHP webshells Unauthenticated file upload in Wholesale Lead Capture (CVE-2026-27540) is being used to plant backdoors on WordPress stores. Wordfence has blocked 100,000+ attempts. Update to 2.0.3.2 and hunt for unexpected PHP files. Patch internet-facing email gateways and vCenter first — those two have the shortest fuse this week. #Cybersecurity #CISA #NIST

    Post summary

    The bulletin emphasizes multiple CVEs being actively exploited, including targeted attacks, CISA KEV inclusion, ransomware exploitation, live attacks, and large-scale abuse attempts. It also provides patch/update guidance, but active exploitation is the dominant theme.

    10000189
    92 followersView on X
  • TwitGri@TwitGri
    Active Exploitation

    ⚠️ WordPress/WooCommerce : CVE-2026-27540 est activement exploitée sur Wholesale Lead Capture. Wordfence dit avoir bloqué +100 000 tentatives. Versions ≤2.0.3.1 : passez en 2.0.3.2+ et cherchez des PHP/webshells suspects. #Cyber #WordPress

    Post summary

    CVE-2026-27540 is being actively exploited against WooCommerce's Wholesale Lead Capture plugin, with Wordfence blocking over 100,000 attacks; users should upgrade to version 2.0.3.2+ and look for malicious PHP/webshells.

    0001034
    37 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploited CVE-2026-27540 to upload PHP webshells through unauthenticated file upload in WooCommerce plugin. Wordfence blocked 100K+ attempts as attackers escalated to full WordPress admin access and established persistent C2. Runtime segmentation helps contain post-compromise lateral movement. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/woocommerce-wholesale-lead-capture-cve-2026-27540-php-webshell

    Post summary

    Attackers exploited CVE-2026-27540 through an unauthenticated file upload in the WooCommerce plugin to upload PHP webshells, gaining full WordPress admin access and establishing persistent C2, while Wordfence blocked over 100,000 attempts and runtime segmentation helped contain further lateral movement.

    0001067
    2.0K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-27540, an unauthenticated file-upload flaw in WooCommerce Wholesale Lead Capture 2.0.3.1 and older, has seen 100,000+ blocked attacks. Exploitation abuses the wwlc_file_upload_handler AJAX action to drop shell.php. #DFIR_Radar https://t.co/PngpsvtFGx

    Post summary

    The tweet reports that CVE-2026-27540, an unauthenticated file-upload vulnerability in WooCommerce Wholesale Lead Capture 2.0.3.1 and older, has seen over 100,000 blocked attacks. It also describes the exploitation method involving the wwlc_file_upload_handler AJAX action and dropping shell.php.

    10000139
    1.9K followersView on X
  • protect_cyber_sec@AmirHossein_sec
    Patch

    برای پلاگین WooCommerce در Wordpress آسیب پذیری با کد شناسایی CVE-2026-27540 منتشر شده است ، این آسیب پذیری به هکرها توانایی بارگزاری و upload فایل php یا به عبارتی همان webshell رو میده ، پلاگین های نسخه 2.0.3.1 و قبل از آن دارای این آسیب پذیری می باشند. به روز رسانی کنید. https://t.co/D15bwIn6No

    Post summary

    The text discloses CVE-2026-27540 in WooCommerce versions 2.0.3.1 and earlier, describing PHP/webshell upload capability. Its primary actionable message is to update the plugin, so it is classified as Patch.

    1000067
    207 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-27540 (CVSS 9.8): Unauthenticated arbitrary file upload in WooCommerce Wholesale Lead Capture lets attackers drop PHP webshells and achieve full RCE. Actively exploited, 100k+ blocked attempts since February. - CVE-2026-27540 affects the wwlc_file_upload_handler AJAX endpoint, reachable with zero authentication. The flaw: allowed file types are read from the attacker-controlled file_settings POST parameter, not server-side config. An attacker simply includes "php" in that forged JSON list, bypasses extension checks, and uploads a .php webshell directly into the WordPress uploads directory. test_type is explicitly set to false in the upload call, killing WordPress's own MIME check too. - Real attack traffic shows POST requests to /wp-admin/admin-ajax.php with action=wwlc_file_upload_handler carrying shell.php, a webshell that fingerprints the host and provides a browser upload form for staging further payloads. Top offending IPs: 92.241.13[.]213, 31.59.129[.]150, 2a0f:85c1:840:5389[.]1, 92.241.13[.]140, 23.137.105[.]214. - Exploitation peaks hit June 4-17, July 1, and August 30, 2026. Roughly 6,000 installations are exposed. Patch version 2.0.3.2 exists; anything at or below 2.0.3.1 is vulnerable. Grep web server access logs for POST /wp-admin/admin-ajax.php containing wwlc_file_upload_handler, then audit wp-content/uploads for unexpected .php files and review wp_users for unknown administrator accounts added post-compromise. #DFIR_Radar

    Post summary

    CVE-2026-27540 is an actively exploited unauthenticated file‑upload vulnerability in WooCommerce Wholesale Lead Capture that enables RCE via PHP webshells, with a patch version 2.0.3.2 available.

    10000156
    1.9K followersView on X
  • Nxploited@Nxploited
    Exploit

    Mass Exploit for CVE-2026-27542 Unauthenticated Privilege Escalation CVE-2026-27540 Unauthenticated Arbitrary File Upload #Wordpress #CyberSecurity #Exploit #Upload GITHUB : HTTPS://GITHUB.COM/NXPLOITED TELEGRAM : @KNXPLOITED https://t.co/Biwme9wUe9

    Post summary

    The post announces a mass exploitation effort against two WordPress CVEs, shares a GitHub link to exploit code, but provides no patch or mitigation details.

    00010143
    90 followersView on X
  • Dominik@GronskiDev

    PSA dla każdego, kto ma sklep na WooCommerce. Trwa aktywna kampania ataków przez wtyczkę Wholesale Lead Capture (CVE-2026-27540). Napastnicy wgrywają na podatne sklepy plik, który daje im kontrolę nad całą stroną. Łatka jest, wersja 2.0.3.2, ale atak rozkręcił się teraz, więc liczy się, kto zdąży zaktualizować. Nie masz tej wtyczki? Dobrze. Ale to i tak dobry moment, żeby wejść w panel i sprawdzić wszystkie wtyczki naraz. Jedna nieaktualna wystarczy. Reguła, która oszczędza nieprzespane noce: wtyczkę, której nie używasz, usuń, nie wyłączaj. Wyłączona dalej leży na serwerze i dalej ma dziury.

    0000038
    20 followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    WordPress WooCommerce の脆弱性 CVE-2026-27540:PHP バックドアのアップロードを確認 https://iototsecnews.jp/2026/09/15/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/ WordPress 向けプラグインである WooCommerce Wholesale Lead Capture において、認証なしで任意のファイルをアップロード可能な脆弱性 CVE-2026-27540 が確認されています。処理時の拡張子チェックを通過され悪意のあるファイルを保管してしまう仕様が背景にあります。この問題により、Web Shell の配置/サーバーの制御権限の奪取/新たな悪意あるコードの追加書き込みといった甚大な影響が発生します。被害を防ぐため、最新版へのアップデート/不審な PHP ファイルの走査/アクセスログの確認/管理者アカウントの精査/安全なデータからの復元などの措置が求められます。 #CVE202627540 #Vulnerability #Woocommerce #WordPress

    Post summary

    The article reports active exploitation of CVE-2026-27540 in the WooCommerce Wholesale Lead Capture plugin, confirming PHP backdoor uploads in the wild, and provides detailed technical analysis alongside urgent remediation steps.

    00000136
    515 followersView on X
  • BT Haberler@BTHaberler
    Active Exploitation

    WooCommerce Eklentisindeki Kritik Açığa Karşı Son 3 Ayda 100.000'den Fazla Saldırı Denemesi Engellendi! WooCommerce Wholesale Lead Capture eklentisinin 2.0.3.1 ve öncesi sürümlerini etkileyen CVE-2026-27540 (CVSS 9.8), dosya yükleme işleyicisindeki (wwlc_file_upload_handler) dosya türü doğrulama eksikliğinden kaynaklanıyor; kimlik doğrulaması olmayan saldırganlar bu açık üzerinden PHP web shell yükleyerek siteyi tamamen ele geçirebiliyor. • Wordfence, Haziran 2026'dan bu yana 100.000'den fazla istismar denemesini engellediğini, son 24 saatte de 99 yeni saldırı kaydettiğini bildirdi. • Eklentinin sadece 6.000'den fazla aktif kurulumu bulunmasına rağmen saldırı hacminin bu denli yüksek olması, otomatik tarama botlarının küçük eklentileri bile sistematik olarak taradığını gösteriyor. Sadece birkaç bin kurulumu olan küçük bir eklentinin bile yüz binlerce otomatik saldırı denemesine maruz kalabilmesi, WordPress ekosisteminde "az kullanılan eklenti daha güvenlidir" varsayımının gerçeği yansıtmadığını gösteriyor. #SiberGüvenlik #WordPress #WooCommerce

    Post summary

    The post reports active exploitation of CVE-2026-27540, with Wordfence blocking more than 100,000 attempts in three months and 99 new attacks in 24 hours. It includes technical vulnerability details and a named payload, but no PoC or patch/workaround is mentioned.

    0000037
    44 followersView on X
  • sunil kumawat@Sunil_kumawat17
    Active Exploitation

    @Phil24275443 CVE-2026-27540 is unauthenticated file upload on wwlc_file_upload_handler — Wordfence has seen shell.php drops via forged file_settings. Patch to 2.0.3.2+, then grep uploads for unexpected .php and admin-ajax hits with that action.

    Post summary

    The tweet reports active in-the-wild exploitation of CVE-2026-27540 (unauthenticated file upload) with observed malicious shell uploads, and urges immediate patching to version 2.0.3.2+ along with log review for indicators of compromise.

    0000038
    23 followersView on X

Explore more