Tech
WooCommerce Wholesale Lead Capture CVE-2026-27540: Arbitrary File Upload Leading to Web Shell Deployment
1. Basic Information
Original Title: Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
Source: Wordfence, BleepingComputer
Published: 2026-09-14
Updated: None
Severity: Critical
Severity Rationale: Attack attempts targeting an unauthenticated arbitrary file upload vulnerability with a CVSS score of 9.8 have been observed. In environments configured to execute PHP in the upload directory, this leads to code execution and site comprom...
Read the full discussion on Dev.to
This article was aggregated from Dev.to. Click to join the conversation.
View on Dev.to