CVE-2026-27542Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

7.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 5 mentions (2026-03-19); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-02-25: 1Mentions · 2026-03-19: 5Mentions · 2026-04-11: 1Mentions · 2026-08-14: 1PoC Mentioned / Linked · 2026-02-25: 1Exploit Tool / Code · 2026-02-25: 1Active Exploitation · 2026-02-25: 1Active Exploitation · 2026-04-11: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-19: 5Technical Details · 2026-04-11: 1Technical Details · 2026-08-14: 102-2503-1904-1108-14
Signal classification3 categories
Disclosure
675.0%
Exploit
112.5%
Active Exploitation
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-251
Exploit1
2026-03-195
Disclosure5
2026-04-111
Active Exploitation1
2026-08-141
Disclosure1
Full discourse8 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-27542 - critical 🚨 WooCommerce Wholesale Lead Capture &lt;= 2.0.3.1 - Unauthenticated Privilege Escalation &gt; Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture &lt;= 2.0.3.1 contains a broke... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27542 @pdnucle...

    Post summary

    A Twitter post announces a critical unauthenticated privilege escalation vulnerability (CVE-2026-27542) in WooCommerce Wholesale Lead Capture versions <=2.0.3.1, with a link to a Project Discovery page for more information.

    040151549
    1.3K followersView on X
  • Nxploited@Nxploited
    Exploit

    Mass Exploit for CVE-2026-27542 Unauthenticated Privilege Escalation CVE-2026-27540 Unauthenticated Arbitrary File Upload #Wordpress #CyberSecurity #Exploit #Upload GITHUB : HTTPS://GITHUB.COM/NXPLOITED TELEGRAM : @KNXPLOITED https://t.co/Biwme9wUe9

    Post summary

    The tweet announces mass exploitation of CVE‑2026‑27542 and CVE‑2026‑27540, links to a GitHub repo likely containing PoC/exploit code, and implies active abuse in the wild.

    00010143
    90 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2026-27542 Exploit in the wild confirmed for CVE-2026-27542 (CVSS 9.8). Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholes... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE-2026-27542 has been reported as actively exploited in the wild with a high CVSS score, although no patch or PoC details are shared in the tweet.

    0000080
    5.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27542 Incorrect Privilege Assignment in Woocommerce Wholesale Lead Capture Through 2.0.3.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27542

    Post summary

    The text announces CVE-2026-27542, indicating an incorrect privilege assignment flaw in Woocommerce Wholesale Lead Capture through version 2.0.3.1.

    0000036
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27542 - Critical Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture... https://www.thehackerwire.com/vulnerability/CVE-2026-27542/ https://t.co/fZhyaHZ8U1

    Post summary

    The message announces a newly identified privilege‑escalation vulnerability (CVE‑2026‑27542) in Woocommerce Wholesale Lead Capture, providing basic technical details but no proof‑of‑concept, exploit code, or patch information.

    0000056
    138 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27542: CRITICAL] Vulnerability in Rymera Web Co Pty Ltd.'s Woocommerce Wholesale Lead Capture plugin allows Privilege Escalation from versions n/a to 2.0.3.1. #CyberSecurity#cve,CVE-2026-27542,#cybersecurity https://cvefind.com/CVE-2026-27542

    Post summary

    The text announces a critical privilege escalation vulnerability targeting the Woocommerce Wholesale Lead Capture plugin up through version 2.0.3.1, offering no proof of concept, exploitation details, or patch information.

    0000056
    604 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27542 Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture allows Privilege Escalation.This issue affects Woocommerce W… https://www.cve.org/CVERecord?id=CVE-2026-27542

    Post summary

    The post announces CVE-2026-27542 as an Incorrect Privilege Assignment flaw in Woocommerce Wholesale Lead Capture enabling privilege escalation, with no PoC, exploit, patch, or active exploitation details provided.

    0000066
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27542: WordPress Woocommerce Wholesale ... WooCommerce wholesale plugin drops admin privileges to unauthenticated users - CVSS 9.8 with zero interaction required ... https://zerodaysignal.com/vulnerability/CVE-2026-27542 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-27542 is a severe privilege‑escalation vulnerability in WooCommerce Wholesale, allowing unauthenticated users to obtain admin rights with zero interaction and a CVSS score of 9.8.

    0000043
    155 followersView on X

Explore more