Toggle light / dark theme

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.

The flaw is tracked as CVE-2026–27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vulnerability discovered by security researcher Teemu Saarentaus.

An attacker can exploit it to upload PHP webshells and execute code, potentially leading to a complete site compromise.

Leave a Comment

Lifeboat Foundation respects your privacy! Your email address will not be published.

/* */