CVE Tools

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

The Hacker NewsBy The Hacker News

Reported exploitedWooCommerce Wholesale Lead CaptureThe Events Calendar

Our summary

Attackers are actively exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture, affecting all versions up to and including 2.0.3.1. The missing file-type validation lets unauthenticated attackers upload PHP web shells, enabling remote code execution and further compromise of WordPress sites. Separately, The Events Calendar is affected by CVE-2026-78159 in versions <= 6.17.3 and CVE-2026-78006 in versions <= 6.17.4; both can lead to unauthenticated remote code execution when event comments are enabled. StellarWP fixed these issues in versions 6.17.3.1 and 6.17.4.1, while WooCommerce Wholesale Lead Capture users should investigate unexpected PHP files and suspicious wwlc_file_upload_handler requests.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store