A critical security flaw in the Wholesale Lead Capture Plugin for WooCommerce is actively being exploited to target WordPress websites with malicious PHP backdoors.
Tracked as CVE-2026-27540, the vulnerability carries a severity rating of 9.0 out of 10. The unauthenticated arbitrary file-upload bug allows unauthenticated attackers to upload malicious code—including PHP webshells (shell.php)—directly onto vulnerable servers. Once injected, hackers can inspect server configurations, gain remote control, and potentially execute a complete website takeover.
According to researchers at Defiant (Wordfence), over 100,000 attack attempts have been blocked across multiple spike periods.
Although the vendor released a patch (v2.0.3.2) in February, thousands of WooCommerce sites remain unupdated. Website administrators using the plugin are strongly urged to update immediately to the latest version and inspect their site upload directories for unfamiliar PHP files.