CVE-2026-27540: WooCommerce Wholesale Lead Capture RCE — Update Now

CVE-2026-27540 is a critical (CVSS 9.8) unauthenticated arbitrary file-upload vulnerability in Wholesale Lead Capture for WooCommerce, and it’s not theoretical — Wordfence has already blocked more than 100,000 exploitation attempts against it, and researchers at multiple outlets have confirmed attackers actively planting PHP web shells through this exact flaw. If this plugin is active on a WooCommerce store you manage, this needs checking today, not this week.

How the Attack Works

The vulnerability lives in the plugin’s wwlc_file_upload_handler AJAX action, which processes files submitted through the plugin’s wholesale registration form — the feature that lets a business customer apply for wholesale pricing and attach supporting documents. The handler doesn’t properly validate what type of file is actually being submitted. An unauthenticated attacker can manipulate the upload request to submit an executable PHP file where the form expects a document or image, and the server accepts and stores it — handing the attacker a working web shell with no login required at any point.

Who’s Affected

Version Status
2.0.3.1 and earlier Vulnerable — actively exploited, update immediately
2.0.3.2 or later Patched

What to Do Right Now

  1. Update Wholesale Lead Capture for WooCommerce to 2.0.3.2 or later immediately — given confirmed active exploitation, this isn’t optional.
  2. Check your uploads directory for unfamiliar PHP files, particularly anywhere the plugin’s wholesale registration attachments are stored.
  3. Review recent wholesale registration submissions for anything unusual — a file submitted with a suspicious extension or name is a strong signal of an attempted or successful exploit.
  4. If you find an unfamiliar PHP file, treat it as a confirmed compromise, not just exposure — a webshell already dropped survives a plugin update.

Why This Plugin Specifically Is a Common Blind Spot

Wholesale/B2B pricing add-ons are exactly the kind of plugin that gets installed once for a specific business need, configured, and then rarely revisited — unlike a core page builder or security plugin that stays on an admin’s radar. That makes vulnerabilities in niche functional plugins like this one disproportionately dangerous: the update notification exists, but the plugin itself isn’t part of anyone’s regular mental checklist.

If you find signs of a completed compromise, we cover the recovery process in WordPress Site Hacked? Here’s the Recovery Checklist We Actually Use. Want a store checked directly? Get in touch.

Frequently Asked Questions

Do I need to have wholesale registration enabled for this to matter?

The exploit path runs through the plugin’s file-upload handler specifically, which is tied to the wholesale registration feature — if the plugin is active at all, the vulnerable code is present and reachable.

Is 100,000 blocked attempts a lot for a plugin with only ~6,000 installs?

Yes — that ratio reflects how automated exploitation works: attackers scan broadly for the plugin’s signature across the entire web, not just sites they know are running it, so blocked-attempt counts routinely dwarf the install base.

Does updating remove a webshell that’s already been planted?

No. Updating closes the vulnerability going forward but does nothing to files an attacker already uploaded before you patched. Check your uploads directory regardless of when you update.

Featured image: original illustration.


Ready to start your project?

Share your brief and we’ll propose the right approach — a full site, a landing page, or a custom plugin.