socradar.io 16 Sept 2026, 11:49 UTC

Attackers Exploit WooCommerce Plugin Flaw to Upload PHP Web Shells

Attackers Exploit WooCommerce Plugin Flaw to Upload PHP Web Shells
CyberSIXT Evidence Panel Source marked as original reporting
CISA KEV Not in KEV
Patch Patch Status Unknown

ATTACKERS are actively targeting CVE-2026-27540, a critical unauthenticated arbitrary file-upload vulnerability in Rymera Web Co’s Wholesale Lead Capture Plugin for WooCommerce. The flaw, classified as CWE-434 and rated 9.8 Critical by Wordfence, affects version 2.0.3.1 and earlier; it was fixed in version 2.0.3.2. The plugin reportedly has more than 6,000 active installations, although that figure does not show how many remain vulnerable or have been compromised.

The vulnerable `wwlc_file_upload_handler` AJAX action does not properly validate uploaded file types, potentially allowing an unauthenticated attacker to submit executable PHP instead of an expected document or image. If the file can run on the server, this may enable remote code execution and activities such as deploying a web shell, changing site files, creating accounts or stealing data.

Wordfence says its firewall has blocked more than 100,000 exploitation attempts, mainly between 4 and 17 June 2026, with further spikes on 1 July and 30 August. The attempts demonstrate active targeting, but do not confirm how many systems were successfully compromised.

Site operators should upgrade immediately to version 2.0.3.2 or later, or temporarily disable or remove the plugin if updating is not possible. Organisations should review logs for suspicious requests to `admin-ajax.php` involving `wwlc_file_upload_handler`, inspect upload directories for unexpected PHP files, and check for unexplained administrator accounts, altered plugin or theme files, `.htaccess` changes, scheduled tasks and unusual outbound connections. Any suspected compromise should be investigated while preserving evidence, followed by appropriate credential and session changes.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline