importantSYS.SOURCE: The Hacker News• 2026-09-16T11:18:28+05:30
Critical WooCommerce Plugin Vulnerability Exploited for PHP Web Shell Deployment
A critical vulnerability in the WooCommerce Wholesale Lead Capture plugin (CVE-2026-27540) allows unauthenticated attackers to upload PHP web shells for remote code execution. Two additional critical flaws in The Events Calendar plugin were also disclosed, enabling unauthorized remote code execution and potential site takeovers.
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.
"This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said.
The WordPress security company said it has blocked over
*** END OF TRANSMISSION ***