Critical severity9.0NVD Advisory· Published Mar 19, 2026· Updated Jun 17, 2026
CVE-2026-27540
CVE-2026-27540
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <=2.0.3.1
- Range: <=2.0.3.1
Patches
Vulnerability mechanics
References
1News mentions
4- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin BugInfosecurity Magazine · Sep 16, 2026
- Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web ShellsThe Hacker News · Sep 16, 2026
- Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without LoginCyber Security News · Sep 15, 2026
- Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture PluginWordfence Blog · Sep 14, 2026