A significant security vulnerability in the WooCommerce Wholesale Lead Capture plugin is currently being exploited by remote attackers, enabling them to upload malicious files and potentially gain full control over vulnerable WordPress sites This article explores security vulnerability woocommerce. . This vulnerability, identified as CVE-2026-27540, affects WooCommerce Wholesale Lead Capture versions 2.0.3.1 and earlier.

The plugin, used by an estimated 6,000 websites, assists in building wholesale-registration forms and supports file uploads as part of the registration process. Security researchers publicly disclosed the issue on February 20, 2026, and it received a CVSS score of 9.8, placing it in the critical category. Attackers have been targeting this weakness for months, with heightened activity observed between June 4 and June 17, as well as on July 1 and August 30.

WooCommerce Flaw Enables Site Takeover WooCommerce Wholesale Lead Capture features an AJAX upload handler named wwlc_file_upload_handler. Additionally, the upload process disables a standard file type validation check, thereby increasing the risk of accepting potentially dangerous server-side files. This backdoor could enable the attacker to execute commands on the server, create unauthorized administrator accounts, steal website data, modify pages, install additional malware, or take control of the entire WordPress installation.