Skip to content
Writing
By MD Jehad H.··4 min read·Operator playbook

The WooCommerce plugin vulnerability worth checking today

Drafted through my n8n + AI pipeline, edited by me.

A file-upload flaw in a niche WooCommerce add-on has been under active attack for months, and most of the stores running it still have not patched.

The plugin is WooCommerce Wholesale Lead Capture, a premium tool from Rymera Web Co that lets B2B and wholesale sellers gate pricing and lead forms behind a login. It sits on roughly 6,000 stores, which is small as WordPress plugins go, and that small footprint is part of why the problem has stayed quiet instead of loud.

What the WooCommerce plugin vulnerability actually does

The flaw is tracked as CVE-2026-27540 and rated 9.8 out of 10 by Wordfence. An AJAX handler in the plugin, wwlc_file_upload_handler, trusts a file extension allowlist sent by the visitor instead of checking it on the server. Anyone, logged in or not, can rewrite that list to include php, upload a web shell disguised as an attachment, and get a script running on your server with no password required.

Flow diagram of the CVE-2026-27540 attack chain from an unauthenticated request to a persistent backdoor

  1. 01Trigger

    Unauthenticated AJAX request

    targets wwlc_file_upload_handler directly

  2. 02Decision

    Extension allowlist overridden

    the file_settings parameter adds php

  3. 03Alert

    PHP web shell uploaded

    stored in the public uploads folder

  4. 04Alert

    Backdoor persists

    new admin account or scheduled task added

  5. 05Human

    Someone finally checks the logs

    usually weeks or months later

Wordfence has blocked more than 100,000 attempts to run this chain, on a patch that has existed since February.

Why this one is easy to miss

The plugin was patched in version 2.0.3.2 back on February 20, 2026, seven months before this week's coverage. Wordfence logged attack spikes from June 4 through 17, again on July 1, and again on August 30, and has now blocked more than 100,000 exploitation attempts against sites still running the old version. If you installed this plugin once to gate wholesale pricing and never thought about it again, that update notice has probably been sitting unread since February.

What to do this week

  1. 1

    Check your plugin list

    Log into wp-admin, go to Plugins, and search for WooCommerce Wholesale Lead Capture. If it is not there, you are not exposed to this one.

  2. 2

    Update to 2.0.3.2 or later

    If you have it, update now. Treat this as a same-day task, not something for the next maintenance window.

  3. 3

    Search your uploads folder for PHP files

    Check wp-content/uploads for any .php files. Nothing in that folder should ever be a script.

  4. 4

    Review admin-ajax.php in your server logs

    Look for requests referencing wwlc_file_upload_handler. Repeated hits there mean someone tried this against you, even if it failed.

  5. 5

    Check your admin user list

    An unfamiliar administrator account is the clearest sign of a successful break-in. Remove it and rotate every password and API key on the site.

If you find a web shell

Do not just delete the file and move on. Restore from a clean backup, rotate all credentials, and assume anything the shell touched is compromised.

None of this needs a security team, just twenty minutes and a plugin list. If you want a second set of eyes on your WordPress stack, or want a check like this built into a recurring workflow instead of a once-a-year scramble, bring me what you're running and we'll look at it together.

Building something this should run inside?

Book a systems call

Keep reading