Hackers target WordPress sites via third-party WooCommerce plugin
Reported exploitedWordPressWooCommerce Wholesale Lead CaptureOur summary
Attackers are actively exploiting CVE-2026-27540 in AutoPlugins LLC's WooCommerce Wholesale Lead Capture for WordPress versions 2.0.3.1 and older. The unauthenticated file-upload flaw lets attackers upload PHP webshells, execute code, and potentially take over affected WordPress sites; administrators should upgrade to version 2.0.3.2 or later and investigate unexpected PHP uploads and related AJAX requests.
Read at BleepingComputer
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.