Security News

Unpatched WooCommerce Plugin Flaw Still Letting Attackers Plant Webshells on WordPress Sites

Infosecurity Magazine · 17 Sept 2026
Key Takeaway If your business uses the WooCommerce Wholesale Lead Capture plugin, update to version 2.0.3.2 or later immediately and check your uploads folder and server logs for signs of unauthorised PHP files.

Security researchers at Wordfence say attackers have launched more than 100,000 exploitation attempts against a critical flaw in WooCommerce Wholesale Lead Capture, a premium plugin from Rymera Web Co used on an estimated 6,000 sites. The vulnerability, tracked as CVE-2026-27540, was patched in version 2.0.3.2 back on February 20, yet sites still running older versions remain exposed.

The flaw sits in the plugin's file upload feature, which is meant to handle wholesale registration forms. Because the list of allowed file types is read from the incoming request rather than checked properly on the server, an attacker who is not even logged in can trick the system into accepting a PHP file instead of a document or image. Wordfence found attackers exploiting this to upload webshells, often named shell.php, which then let them view server details and upload further malicious files, effectively taking control of parts of the site.

Exploit activity spiked between June 4 and June 17, with further waves in July and August, meaning the threat has continued well after the fix was made available. All plugin versions up to and including 2.0.3.1 are vulnerable.

WordPress WooCommerce Webshell Plugin Vulnerability Patch Management

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.