CVE Tools

Hackers target WordPress sites via third-party WooCommerce plugin

BleepingComputerBy Bill Toulas

Reported exploitedWordPressWooCommerce Wholesale Lead Capture

Our summary

Attackers are actively exploiting CVE-2026-27540 in AutoPlugins LLC's WooCommerce Wholesale Lead Capture for WordPress versions 2.0.3.1 and older. The unauthenticated file-upload flaw lets attackers upload PHP webshells, execute code, and potentially take over affected WordPress sites; administrators should upgrade to version 2.0.3.2 or later and investigate unexpected PHP uploads and related AJAX requests.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store