CVE-2026-27540 (Critical): An unauthenticated arbitrary file-upload vulnerability in WooCommerce Wholesale Lead Capture. The plugin exposes the wwlc_file_upload_handler AJAX action and relies on a user-controlled file_settings parameter to determine permitted file extensions. Attackers can manipulate this parameter to allow .php files and upload a PHP webshell, which can then be accessed to execute arbitrary commands on the server.
We recommend you to update WooCommerce Wholesale Lead Capture to version 2.0.3.2 or later.[/subscribe_to_unlock_form]
CVE-2026-27540 (Critical): An unauthenticated arbitrary file-upload vulnerability in WooCommerce Wholesale Lead Capture. The plugin exposes the wwlc_file_upload_handler AJAX action and relies on a user-controlled file_settings parameter to determine permitted file extensions. Attackers can manipulate this parameter to allow .php files and upload a PHP webshell, which can then be accessed to execute arbitrary commands on the server.
We recommend you to update WooCommerce Wholesale Lead Capture to version 2.0.3.2 or later.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]