LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

zeroday.news ·

Attackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress, enabling them to upload PHP backdoors to compromised sites. The flaw, identified as CVE-2026-27540, affects plugin versions 2.0.3.1 and older.

The vulnerability is an unauthenticated arbitrary file-upload issue that could lead to complete site compromise through remote code execution. Security researcher Teemu Saarentaus discovered the flaw.

The technical root of the vulnerability lies in the exposure of an unauthenticated AJAX action, `wwlc_file_upload_handler`. This action processes file uploads and checks file extensions against an allowlist. Crucially, the allowlist is supplied through a user-controlled request parameter, `file_settings`, which allows attackers to add `.php` to the permitted file types. This enables the plugin to accept executable PHP file uploads.

During attacks, threat actors submit a request to the `wwlc_file_upload_handler` AJAX action, including a forged `file_settings` parameter and a malicious file with a `.php` extension. The uploaded file, typically named `shell.php`, functions as a PHP webshell. This webshell can perform reconnaissance on the host and provides a browser-based upload form for writing additional malicious files to the compromised site.

The vulnerability was addressed in version 2.0.3.2 of the WooCommerce Wholesale Lead Capture plugin, which was released on February 20.

Despite the availability of a patch, a WordPress security company has reported blocking over 100,000 attacks related to CVE-2026-27540. Exploitation activity has shown significant spikes, particularly between June 4 and June 17, and again on July 1 and August 30.

Administrators of WordPress sites using the affected plugin are strongly advised to upgrade to version 2.0.3.2 or later immediately. Additionally, it is recommended to check upload directories for any unexpected or recently created PHP files and to examine logs for requests to `/wp-admin/admin-ajax.php` that invoke `wwlc_file_upload_handler`. Any unknown administrator accounts should also be removed.

If a compromise is confirmed, the recommended course of action is to restore the website from a safe backup. Attempting to manually remove all persistence mechanisms, malicious users, and backdoors can be complex and may not fully secure the site.

vulnerabilitynation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s