woocommerce-store

A popular plugin for WooCommerce stores, “Wholesale Lead Capture,” has a vulnerability that is being actively exploited: attackers upload a PHP file and can take over the entire site.

Many online stores and showcase websites are built on WordPress, and plugins are added to WooCommerce to provide various features. One of them, “Wholesale Lead Capture for WooCommerce,” used to collect wholesale orders, contains the CVE-2026-27540 vulnerability.

The problem stems from a file upload form that was left open without requiring authentication. An attacker can trick the plugin into accepting a PHP file and upload it to the site—essentially a small control program called a webshell. From there, the attacker can add more code, create administrator accounts, and take complete control of the site. The security firm Wordfence has blocked over 100,000 such attempts; the fix is available in version 2.0.3.2 of the plugin, while older versions remain vulnerable.

For a small business, a compromised website isn't just a broken page: it can spread malware to visitors, steal customer data, and take the online store offline just when it's generating sales.

What you need to do:

  • Ask whoever manages your website if you’re using the “Wholesale Lead Capture” plugin and if it’s updated to version 2.0.3.2 or newer.
  • Ask them to check if any unknown PHP files have appeared in the uploads folders or if there are any administrator accounts you don’t recognize.
  • If there are signs of a security breach, the safest course of action is to restore the site from a clean backup.

Sources:

  • BleepingComputer | https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/
  • Wordfence | https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/

This article was generated with AI assistance.

Request a quote

← All news