If your store runs on WooCommerce and you added the Wholesale Lead Capture plugin to onboard B2B buyers, stop and check its version right now. CVE-2026-27540 is a critical, unauthenticated file-upload flaw in that plugin, rated CVSS 9.0, and it lets anyone on the internet drop a PHP webshell onto your server and take the whole store over. This is not theoretical: Wordfence has already blocked more than 100,000 attempts against it. A patch exists, but the window between “released” and “installed” is exactly where sites are being lost.
What CVE-2026-27540 actually is
The WooCommerce Wholesale Lead Capture plugin exposes an AJAX action, wwlc_file_upload_handler, that handles file uploads during wholesale registration. The problem is that this action is reachable without authentication, so no login is required to call it. On its own an open upload endpoint is bad enough, but the real defect is how it decides which files are allowed.
Instead of checking uploads against a fixed list of safe extensions held on the server, the plugin reads the list of permitted file types from a request parameter the caller controls, file_settings. In other words, the attacker supplies both the file and the rules for what counts as an acceptable file. Add “php” to that list, upload a PHP script, and the plugin happily accepts an executable webshell. From there the attacker runs arbitrary code as your web server, and the site is theirs.
| Detail | Value |
|---|---|
| CVE | CVE-2026-27540 |
| CVSS | 9.0, critical |
| Plugin | WooCommerce Wholesale Lead Capture (premium) |
| Flaw | unauthenticated arbitrary file upload → PHP webshell |
| Affected | version 2.0.3.1 and earlier |
| Fixed in | version 2.0.3.2 (released 20 February 2026) |
| In the wild | 100,000+ attempts blocked by Wordfence; ~6,000 sites run the plugin |
The real lesson: never trust the client to set its own rules
It is worth pausing on why this bug exists, because the pattern is common and avoidable. A security control is only a control if the attacker cannot edit it. Here the allowlist of permitted extensions — the one thing standing between a harmless image and an executable script — was handed to the client to define. That is the same mistake as letting a form set its own price, or trusting a hidden field to say whether a user is an admin.
The fix is not clever, it is structural: the server, and only the server, decides what a file upload may contain. Extensions get validated against a hardcoded allowlist, uploaded files are stored outside the web root or with execution disabled, and content type is verified rather than assumed from a name the attacker chose. A source code review catches this class of flaw in minutes, because “trusting user-supplied validation rules” is exactly the kind of thing a reviewer is trained to spot and a scanner often misses.
Why an e-commerce site is the worst place to lose
Arbitrary file upload always sounds serious, but on a store it is close to catastrophic, and that is why the score is a 9.0. A webshell gives the attacker code execution on the same server that processes your orders. From that position the obvious moves are all lucrative: harvest the customer database, hijack an administrator account, and — the one that quietly ruins businesses — inject a payment skimmer into the checkout so every card entered on your site is copied to the attacker in real time.
That last outcome is why this matters far beyond a single defaced page. Card skimming on a compromised store can run for weeks before anyone notices, and it drags in PCI DSS obligations, chargebacks, and a breach disclosure. If you take card payments, the health of every plugin on the site is a compliance question, not just an IT one, which is exactly what a PCI DSS penetration test is meant to surface before an attacker does.
The patch gap is the story
Here is the uncomfortable part. The plugin authors fixed this in version 2.0.3.2, released on 20 February. The 100,000-plus blocked attacks and the ongoing in-the-wild exploitation happened after that — against sites that simply had not updated. The vulnerability is not really “unpatched software”; it is “patched software nobody installed.” Premium plugins make this worse, because updates often depend on an active license and a manual step, so they quietly fall behind while the store keeps selling.
This is the pattern behind most WordPress compromises. The flaw is disclosed, a patch ships, automated exploitation follows within days, and the sites that get hit are the ones running the old version weeks or months later. Speed of patching, not the existence of a patch, is what decides who gets breached. Continuous vulnerability management exists precisely to close that gap, flagging the outdated plugin before a scanner on the other side finds it first.
What to do now
- Update WooCommerce Wholesale Lead Capture to 2.0.3.2 or later immediately. If you cannot update at once, deactivate the plugin until you can.
- Assume compromise if you were exposed. Inspect your uploads directory and the wider site for unfamiliar PHP files, recently modified files, and unexpected scheduled tasks — a webshell usually leaves one of these behind.
- Check your administrators and integrations. Look for admin accounts you did not create and API keys you do not recognise, and rotate credentials, secrets and payment-gateway keys if there is any doubt.
- Scrutinise the checkout specifically. A skimmer hides in the payment flow, so review the checkout code and scripts for anything injected. Managed detection and response and API security monitoring shorten the time between a webshell landing and someone noticing.
- If customer or card data may have left the building, act on it. Dark-web monitoring gives early warning that your customers’ details are circulating, and it starts the clock on breach obligations honestly rather than by surprise.
The bottom line
CVE-2026-27540 is a textbook chain: an unauthenticated endpoint, an allowlist the attacker controls, a PHP webshell, and then your entire store. The plugin has been fixed since February, so the only reason it is still claiming victims is the gap between a patch existing and a patch being installed — and on a store, that gap is measured in stolen cards and leaked customers, not just downtime. Update to 2.0.3.2 today, hunt for anything that may already have been dropped, and treat every third-party plugin on a site that handles money as part of your attack surface. If you are not certain your store is clean or your plugins are current, talk to our team and find out before the next 100,000 attempts include a successful one.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.
