The WooCommerce plugin vulnerability worth checking today
Drafted through my n8n + AI pipeline, edited by me.
A file-upload flaw in a niche WooCommerce add-on has been under active attack for months, and most of the stores running it still have not patched.
The plugin is WooCommerce Wholesale Lead Capture, a premium tool from Rymera Web Co that lets B2B and wholesale sellers gate pricing and lead forms behind a login. It sits on roughly 6,000 stores, which is small as WordPress plugins go, and that small footprint is part of why the problem has stayed quiet instead of loud.
What the WooCommerce plugin vulnerability actually does
The flaw is tracked as CVE-2026-27540 and rated 9.8 out of 10 by Wordfence. An AJAX handler in the plugin, wwlc_file_upload_handler, trusts a file extension allowlist sent by the visitor instead of checking it on the server. Anyone, logged in or not, can rewrite that list to include php, upload a web shell disguised as an attachment, and get a script running on your server with no password required.
Flow diagram of the CVE-2026-27540 attack chain from an unauthenticated request to a persistent backdoor
- 01Trigger
Unauthenticated AJAX request
targets wwlc_file_upload_handler directly
- 02Decision
Extension allowlist overridden
the file_settings parameter adds php
- 03Alert
PHP web shell uploaded
stored in the public uploads folder
- 04Alert
Backdoor persists
new admin account or scheduled task added
- 05Human
Someone finally checks the logs
usually weeks or months later
Why this one is easy to miss
The plugin was patched in version 2.0.3.2 back on February 20, 2026, seven months before this week's coverage. Wordfence logged attack spikes from June 4 through 17, again on July 1, and again on August 30, and has now blocked more than 100,000 exploitation attempts against sites still running the old version. If you installed this plugin once to gate wholesale pricing and never thought about it again, that update notice has probably been sitting unread since February.
What to do this week
- 1
Check your plugin list
Log into wp-admin, go to Plugins, and search for WooCommerce Wholesale Lead Capture. If it is not there, you are not exposed to this one.
- 2
Update to 2.0.3.2 or later
If you have it, update now. Treat this as a same-day task, not something for the next maintenance window.
- 3
Search your uploads folder for PHP files
Check wp-content/uploads for any .php files. Nothing in that folder should ever be a script.
- 4
Review admin-ajax.php in your server logs
Look for requests referencing wwlc_file_upload_handler. Repeated hits there mean someone tried this against you, even if it failed.
- 5
Check your admin user list
An unfamiliar administrator account is the clearest sign of a successful break-in. Remove it and rotate every password and API key on the site.
If you find a web shell
Do not just delete the file and move on. Restore from a clean backup, rotate all credentials, and assume anything the shell touched is compromised.
None of this needs a security team, just twenty minutes and a plugin list. If you want a second set of eyes on your WordPress stack, or want a check like this built into a recurring workflow instead of a once-a-year scramble, bring me what you're running and we'll look at it together.
Building something this should run inside?
Book a systems callKeep reading
wordpress
This WordPress plugin vulnerability needs a same-day fix
A WordPress plugin vulnerability in The Events Calendar is under active attack on over 600,000 sites, and the fix takes ten minutes.
wordpress
WordPress security updates just got more urgent
WordPress security updates are shipping faster after an AI-driven report spike, and a monthly check is no longer a safe patch cadence.
wordpress
The abilities API lets AI run your WordPress
WordPress 7.1 shipped an abilities API that lets AI agents create posts and update inventory on your site. Here is what to expose and what to lock down.