Gbhackers iconGbhackersSep 15, 2026

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

The vulnerability, tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of […]

Hackers Actively Exploit Critical WooCommerce Plugin Vulnerability to Upload PHP Backdoors

Share this story

Send the public story page.

Useful takeaways from this story.

The vulnerability, tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of […]

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full...

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

The vulnerability, tracked as CVE-2026-27540, affects plugin versions 2.0.3.1 and earlier and has received a CVSS severity score of 9.8 out of […] Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites.

Details worth keeping

Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin that lets unauthenticated attackers upload malicious PHP files and potentially seize full control of vulnerable WordPress sites.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app