discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Hackers Target WordPress Sites via Third-Party WooCommerce Plugin

Hackers exploit WooCommerce Wholesale Lead Capture plugin vulnerability to upload PHP backdoor. Wordfence blocks over 100,000 attacks.

By Bill Toulas·Sep 15·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Hackers Target WordPress Sites via Third-Party WooCommerce Plugin
Image: bleepingcomputer.com

Hackers are exploiting a vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload a PHP backdoor, leading to site compromise.

Why it matters

This vulnerability affects WordPress sites using the WooCommerce Wholesale Lead Capture plugin and poses a significant security risk.

Hackers are tricking a plugin to let them upload a file, which can let them take control of a website.

Analysis

{"heading":"Technical Details of the Vulnerability","subheading":"wwlc_file_upload_handler AJAX Action","content":["The vulnerability is caused by an unauthenticated arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin.","The flaw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older.","The plugin exposes an unauthenticated AJAX action named wwlc_file_upload_handler, which checks file extensions against an allowlist supplied through the user-controlled file_settings request parameter."]}

Key points

  • Vulnerability affects WooCommerce Wholesale Lead Capture plugin versions 2.0.3.1 and older.
  • The vulnerability is tracked as CVE-2026-27540.
  • Wordfence's web application firewall blocked over 100,000 attacks linked to the vulnerability.
The Upside

Wordfence's web application firewall can block attacks, and upgrading to the latest plugin version can prevent exploitation.

The Downside

If not detected and blocked, the vulnerability can lead to a complete site compromise.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywordpresswoocommercevulnerabilitywebshells

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 15, 2026

Source

bleepingcomputer.com

Share

Topics

securitywordpresswoocommercevulnerabilitywebshells

Related

More from this desk

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.

Oct 7·krebsonsecurity.com

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

Jordanian teenager detained for leading ShinyHunters, a data theft and extortion group. FBI investigating extortion of Boeing subsidiary Jeppesen ForeFlight.

Oct 7·schneier.com

Apple’s Verified Photography System

Apple introduces a new system called 'Reference Image' to verify iPhone photos without tying them to specific devices or photographers.