Third-party WooCommerce plugin hits WordPress sites with PHP backdoor abusing recently patched vulnerability
- Defiant warned of active exploitation of WooCommerce Wholesale Lead Capture Plugin flaw (CVE‑2026‑27540)
- Critical unauthenticated file‑upload bug lets attackers deploy PHP webshells for site takeover
- Patch released in Feb 2026 (v2.0.3.2); Wordfence blocked 100,000+ attacks, users urged to update and check uploads
A critical vulnerability in a popular WooCommerce plugin is being actively exploited to upload malware and possibly take over entire websites, security experts have warned.
The plugin in question is called Wholesale Lead Capture Plugin for WooCommerce. It adds a dedicated registration and onboarding system for wholesale and B2B customers, letting businesses collect company and other custom information, review applications, assign wholesale user roles, and automate registration and onboarding emails.
It is a premium plugin that costs between $99 and $600 and which, according to the Wordpress store page, has more than 20,000 active installations.
A thousand victims
The plugin was vulnerable to an unauthenticated arbitrary file-upload...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE