AI Weekly Malaysia

Back to items Summaries

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

ID
24981
Status
summarized
Published
16 Sep 2026, 1:48 PM
Fetched
16 Sep 2026, 4:16 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.0
Created
16 Sep 2026, 4:20 PM
Tags
Audience
developersvibe_coderssaas_founders

What happened

Attackers are actively exploiting a critical arbitrary file upload flaw (CVE-2026-27540, CVSS 9.8) in the WooCommerce Wholesale Lead Capture premium plugin, affecting versions up to 2.0.3.1. Wordfence has blocked over 100,000 exploit attempts since June 2026 that upload PHP web shells via the unauthenticated 'wwlc_file_upload_handler' AJAX action.

Why it matters

If your WordPress or WooCommerce site uses this specific premium plugin, you must immediately update it and scan your uploads directory for unexpected .php files. For builders shipping custom AJAX endpoints, this is a concrete reminder to enforce strict server-side file type validation, as missing checks allow unauthenticated users to achieve remote code execution.

Discussion angle

How to properly secure AJAX file upload endpoints in WordPress and custom PHP applications to prevent arbitrary file uploads and remote code execution.

Top