- Threat actors are actively exploiting CVE-2026-27540, a critical arbitrary file upload flaw in the WooCommerce Wholesale Lead Capture plugin with 6,000+ active installs.
- Wordfence has blocked over 100,000 exploit attempts since June 2026, with 99 recorded in the last 24 hours from a range of IP addresses.
- Successful attacks allow unauthenticated upload of PHP web shells, leading to remote code execution and site takeover.
- Separately, two critical flaws (CVE-2026-78159, CVE-2026-78006) in The Events Calendar plugin can be chained for unauthenticated RCE, affecting over 600,000 sites.
Threat actors are actively exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin installed on over 6,000 sites. This vulnerability, tracked as CVE-2026-27540 (CVSS 9.8), allows unauthenticated attackers to upload arbitrary files including PHP backdoors, according to security firm Wordfence.
The flaw resides in an AJAX action called “wwlc_file_upload_handler” that lacks proper file type validation. Attackers submit crafted requests with a forged file_settings parameter and a malicious PHP file, which acts as a web shell that reports host details and enables further file uploads. Wordfence reported that it has blocked over 100,000 exploit attempts since June 2026, with 99 of those recorded in the last 24 hours from IP addresses including 92.241.13.213 and 31.59.129.150. Consequently, site owners are advised to check the uploads directory for unexpected PHP files and review admin-ajax.php requests for the “wwlc_file_upload_handler” action.
Meanwhile, Wordfence also detailed two critical vulnerabilities in The Events Calendar plugin, installed on over 600,000 websites. CVE-2026-78159 (CVSS 9.8) arises from insufficient validation of the widget ‘classes’ map, while CVE-2026-78006 (CVSS 9.8) involves insufficient protection in the “is_safe_widget_instance” function. Both chains can be triggered through WordPress’s pending-comment preview without moderator approval and lead to remote code execution via PHP Object Injection or password reset abuse. StellarWP has addressed these flaws in plugin versions 6.17.3.1 and 6.17.4.1, respectively.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
