Attackers are actively exploiting a critical vulnerability in a third-party WooCommerce plugin, uploading PHP webshells to WordPress sites even though a fix was released four months ago, as first reported by Infosecurity Magazine.The vulnerability, identified as CVE-2026-27540 with a CVSS score of 9.8, exists in the WooCommerce Wholesale Lead Capture plugin. Wordfence reported blocking over 100,000 exploitation attempts against the flaw, which allows unauthenticated attackers to upload executable PHP files. The attackers craft requests to bypass the plugin's file extension check, enabling them to upload webshells. These webshells can then be used to execute further commands and write files to the compromised site.Exploit attempts peaked between June and August. All plugin versions prior to 2.0.3.2 are affected. Site owners are urged to update to version 2.0.3.2 or later, review their upload directories for suspicious PHP files, and check web server access logs for signs of compromise. While a firewall rule can block known exploit attempts, it does not fix the underlying vulnerability.Source: Infosecurity Magazine
