Threat Advisory

WooCommerce Plugin Flaw Lets Attackers Upload PHP Webshells

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-27540 (Critical): An unauthenticated arbitrary file-upload vulnerability in WooCommerce Wholesale Lead Capture. The plugin exposes the wwlc_file_upload_handler AJAX action and relies on a user-controlled file_settings parameter to determine permitted file extensions. Attackers can manipulate this parameter to allow .php files and upload a PHP webshell, which can then be accessed to execute arbitrary commands on the server.

RECOMMENDATION:

We recommend you to update WooCommerce Wholesale Lead Capture to version 2.0.3.2 or later.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-27540 (Critical): An unauthenticated arbitrary file-upload vulnerability in WooCommerce Wholesale Lead Capture. The plugin exposes the wwlc_file_upload_handler AJAX action and relies on a user-controlled file_settings parameter to determine permitted file extensions. Attackers can manipulate this parameter to allow .php files and upload a PHP webshell, which can then be accessed to execute arbitrary commands on the server.

RECOMMENDATION:

We recommend you to update WooCommerce Wholesale Lead Capture to version 2.0.3.2 or later.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu