bleeping-computer · Crawled Sep 15, 2026
Hackers target WordPress sites via third-party WooCommerce plugin
6 IoCs
Read original article ↗
AI Summary
Hackers are actively exploiting a critical unauthenticated arbitrary file-upload vulnerability, CVE-2026-27540, in the WooCommerce Wholesale Lead Capture plugin for WordPress. The flaw allows attackers to upload PHP webshells by manipulating the wwlc_file_upload_handler AJAX action and bypassing file extension checks via a user-controlled parameter. Exploitation attempts have been observed in multiple waves, with over 100,000 attacks blocked by Wordfence. The uploaded webshell, named shell.php, enables host reconnaissance and facilitates deployment of additional malicious payloads.
AI-extracted · verify before operational use