Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
- ID
- 24981
- Status
- summarized
- Published
- 16 Sep 2026, 1:48 PM
- Fetched
- 16 Sep 2026, 4:16 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 4.0
- Created
- 16 Sep 2026, 4:20 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
Attackers are actively exploiting a critical arbitrary file upload flaw (CVE-2026-27540, CVSS 9.8) in the WooCommerce Wholesale Lead Capture premium plugin, affecting versions up to 2.0.3.1. Wordfence has blocked over 100,000 exploit attempts since June 2026 that upload PHP web shells via the unauthenticated 'wwlc_file_upload_handler' AJAX action.
Why it matters
If your WordPress or WooCommerce site uses this specific premium plugin, you must immediately update it and scan your uploads directory for unexpected .php files. For builders shipping custom AJAX endpoints, this is a concrete reminder to enforce strict server-side file type validation, as missing checks allow unauthenticated users to achieve remote code execution.
Discussion angle
How to properly secure AJAX file upload endpoints in WordPress and custom PHP applications to prevent arbitrary file uploads and remote code execution.