discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Hackers Target WordPress Sites via Third-Party WooCommerce Plugin

Hackers exploit WooCommerce Wholesale Lead Capture plugin vulnerability to upload PHP backdoor. Wordfence blocks over 100,000 attacks.

By Bill Toulas·Sep 15·bleepingcomputer.com·1 min read

Intelligence analysis by Qwen 2.5 (3B)

Hackers Target WordPress Sites via Third-Party WooCommerce Plugin
Image: bleepingcomputer.com

Hackers are exploiting a vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload a PHP backdoor, leading to site compromise.

Why it matters

This vulnerability affects WordPress sites using the WooCommerce Wholesale Lead Capture plugin and poses a significant security risk.

Hackers are tricking a plugin to let them upload a file, which can let them take control of a website.

Analysis

{"heading":"Technical Details of the Vulnerability","subheading":"wwlc_file_upload_handler AJAX Action","content":["The vulnerability is caused by an unauthenticated arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin.","The flaw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older.","The plugin exposes an unauthenticated AJAX action named wwlc_file_upload_handler, which checks file extensions against an allowlist supplied through the user-controlled file_settings request parameter."]}

Key points

  • Vulnerability affects WooCommerce Wholesale Lead Capture plugin versions 2.0.3.1 and older.
  • The vulnerability is tracked as CVE-2026-27540.
  • Wordfence's web application firewall blocked over 100,000 attacks linked to the vulnerability.
The Upside

Wordfence's web application firewall can block attacks, and upgrading to the latest plugin version can prevent exploitation.

The Downside

If not detected and blocked, the vulnerability can lead to a complete site compromise.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywordpresswoocommercevulnerabilitywebshells

Author

Bill Toulas

Intelligence analysis by

Qwen 2.5 (3B)

Published

Sep 15, 2026

Source

bleepingcomputer.com

Share

Topics

securitywordpresswoocommercevulnerabilitywebshells

Related

More from this desk

Oct 8·bleepingcomputer.com

Maryland Man Found Guilty of Stealing $53 Million from Decentralized Crypto Exchange Uranium Finance

Maryland man convicted of hacking Uranium Finance, a decentralized crypto exchange, and stealing $53 million in cryptocurrency.

Oct 8·wired.com

The Man Behind a West Bank Telegram Channel Trying to Keep Palestinian Drivers Safe

A Telegram group helps Palestinian drivers navigate checkpoints in the West Bank, where popular navigation apps fail them.

Oct 8·thehackernews.com

U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

The U.S. State Department is offering a $10 million reward for information on Zhang Yu, a Chinese national charged in the 2021 HAFNIUM Microsoft Exchange Server attacks.

Oct 8·thehackernews.com

MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data

The owner of MonsterCloud, Zohar Pinhasi, is accused of defrauding ransomware victims by secretly paying attackers for decryptors while claiming to use proprietary tools. He allegedly charged clients millions more than the ransoms paid.