BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

WooCommerce Plugin Flaw Exploited for PHP Backdoor Attacks

Critical WooCommerce and Events Calendar bugs enable unauthenticated site takeovers.

  • Threat actors are actively exploiting CVE-2026-27540, a critical arbitrary file upload flaw in the WooCommerce Wholesale Lead Capture plugin with 6,000+ active installs.
  • Wordfence has blocked over 100,000 exploit attempts since June 2026, with 99 recorded in the last 24 hours from a range of IP addresses.
  • Successful attacks allow unauthenticated upload of PHP web shells, leading to remote code execution and site takeover.
  • Separately, two critical flaws (CVE-2026-78159, CVE-2026-78006) in The Events Calendar plugin can be chained for unauthenticated RCE, affecting over 600,000 sites.

Threat actors are actively exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin installed on over 6,000 sites. This vulnerability, tracked as CVE-2026-27540 (CVSS 9.8), allows unauthenticated attackers to upload arbitrary files including PHP backdoors, according to security firm Wordfence.

- Advertisement -

The flaw resides in an AJAX action called “wwlc_file_upload_handler” that lacks proper file type validation. Attackers submit crafted requests with a forged file_settings parameter and a malicious PHP file, which acts as a web shell that reports host details and enables further file uploads. Wordfence reported that it has blocked over 100,000 exploit attempts since June 2026, with 99 of those recorded in the last 24 hours from IP addresses including 92.241.13.213 and 31.59.129.150. Consequently, site owners are advised to check the uploads directory for unexpected PHP files and review admin-ajax.php requests for the “wwlc_file_upload_handler” action.

Meanwhile, Wordfence also detailed two critical vulnerabilities in The Events Calendar plugin, installed on over 600,000 websites. CVE-2026-78159 (CVSS 9.8) arises from insufficient validation of the widget ‘classes’ map, while CVE-2026-78006 (CVSS 9.8) involves insufficient protection in the “is_safe_widget_instance” function. Both chains can be triggered through WordPress’s pending-comment preview without moderator approval and lead to remote code execution via PHP Object Injection or password reset abuse. StellarWP has addressed these flaws in plugin versions 6.17.3.1 and 6.17.4.1, respectively.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Two Robinhood Engineers Charged with Insider Crypto Futures Trading

Two former Robinhood engineers were charged with fraud for allegedly trading on confidential insider...

Senate Rejects Crypto Bill; Industry Eyes SEC, CFTC Rules

The Senate failed to advance the CLARITY Act on a 49-50 cloture vote, missing...

Fed Poised to Raise Rates Wednesday, Trump Clash Looms

The Federal Reserve is expected to raise interest rates by 25 basis points on...

Anthropic’s AI doom narrative alleged to boost founder equity

Substack author Kevin Bass claims Anthropic used “AI doom” media narratives to boost Dustin...

Senate vote kills Clarity Act, crypto bill dead

Senators voted down cloture on the motion to proceed to the Clarity Act, blocking...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading