Hackers Target WordPress Sites via Third-Party WooCommerce Plugin
Hackers exploit WooCommerce Wholesale Lead Capture plugin vulnerability to upload PHP backdoor. Wordfence blocks over 100,000 attacks.
Intelligence analysis by Qwen 2.5 (3B)

Hackers are exploiting a vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload a PHP backdoor, leading to site compromise.
Hackers are tricking a plugin to let them upload a file, which can let them take control of a website.
Analysis
{"heading":"Technical Details of the Vulnerability","subheading":"wwlc_file_upload_handler AJAX Action","content":["The vulnerability is caused by an unauthenticated arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin.","The flaw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older.","The plugin exposes an unauthenticated AJAX action named wwlc_file_upload_handler, which checks file extensions against an allowlist supplied through the user-controlled file_settings request parameter."]}
Key points
- Vulnerability affects WooCommerce Wholesale Lead Capture plugin versions 2.0.3.1 and older.
- The vulnerability is tracked as CVE-2026-27540.
- Wordfence's web application firewall blocked over 100,000 attacks linked to the vulnerability.
Wordfence's web application firewall can block attacks, and upgrading to the latest plugin version can prevent exploitation.
If not detected and blocked, the vulnerability can lead to a complete site compromise.


