BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

WooCommerce Plugin Flaw Exploited for PHP Backdoor Attacks

Critical WooCommerce and Events Calendar bugs enable unauthenticated site takeovers.

  • Threat actors are actively exploiting CVE-2026-27540, a critical arbitrary file upload flaw in the WooCommerce Wholesale Lead Capture plugin with 6,000+ active installs.
  • Wordfence has blocked over 100,000 exploit attempts since June 2026, with 99 recorded in the last 24 hours from a range of IP addresses.
  • Successful attacks allow unauthenticated upload of PHP web shells, leading to remote code execution and site takeover.
  • Separately, two critical flaws (CVE-2026-78159, CVE-2026-78006) in The Events Calendar plugin can be chained for unauthenticated RCE, affecting over 600,000 sites.

Threat actors are actively exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin installed on over 6,000 sites. This vulnerability, tracked as CVE-2026-27540 (CVSS 9.8), allows unauthenticated attackers to upload arbitrary files including PHP backdoors, according to security firm Wordfence.

- Advertisement -

The flaw resides in an AJAX action called “wwlc_file_upload_handler” that lacks proper file type validation. Attackers submit crafted requests with a forged file_settings parameter and a malicious PHP file, which acts as a web shell that reports host details and enables further file uploads. Wordfence reported that it has blocked over 100,000 exploit attempts since June 2026, with 99 of those recorded in the last 24 hours from IP addresses including 92.241.13.213 and 31.59.129.150. Consequently, site owners are advised to check the uploads directory for unexpected PHP files and review admin-ajax.php requests for the “wwlc_file_upload_handler” action.

Meanwhile, Wordfence also detailed two critical vulnerabilities in The Events Calendar plugin, installed on over 600,000 websites. CVE-2026-78159 (CVSS 9.8) arises from insufficient validation of the widget ‘classes’ map, while CVE-2026-78006 (CVSS 9.8) involves insufficient protection in the “is_safe_widget_instance” function. Both chains can be triggered through WordPress’s pending-comment preview without moderator approval and lead to remote code execution via PHP Object Injection or password reset abuse. StellarWP has addressed these flaws in plugin versions 6.17.3.1 and 6.17.4.1, respectively.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Anthropic’s AI Cyber Program Uncovers 129,000 Flaws

Anthropic expanded its Cyber Verification Program (CVP) with three access tiers for cybersecurity professionals...

Kalshi gold markets double Ether fees in September

Gold 15-minute contracts on Kalshi generated $5 million in estimated fees in September, nearly...

ARK Invest Buys $16.2M in Archer and Joby Shares

Ark Invest bought 2.57 million Archer Aviation shares for $11.9 million and 753,330 Joby...

Bitcoin Group SE seeks alternative after BaFin denies MiCA

BaFin refused futurum bank AG’s application for authorization as a crypto-asset service provider under...

Google launches Nano Banana 2.1 AI with better accuracy, half price

Google released Nano Banana 2.1 on Oct. 6, rolling it out across the Gemini...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading