Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.
The flaw is tracked as CVE-2026–27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vulnerability discovered by security researcher Teemu Saarentaus.
An attacker can exploit it to upload PHP webshells and execute code, potentially leading to a complete site compromise.
