
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27540 is an Unrestricted File Upload vulnerability (CWE-434) in the WooCommerce Wholesale Lead Capture plugin by Rymera Web Co Pty Ltd, affecting all versions through 2.0.3.1. The flaw allows unauthenticated remote attackers to upload malicious files — including web shells and backdoors — to vulnerable WordPress installations. It was discovered and reported by Teemu Saarentaus and published by Patchstack on February 20, 2026, with NVD publication on March 19, 2026. The vulnerability carries a CVSS v3.1 base score of 9.0 (Critical) (Patchstack, Red Hat CVE).
The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), meaning the plugin fails to properly validate or restrict the file types accepted through its lead capture upload functionality. An unauthenticated attacker can submit a crafted HTTP request to the plugin's file upload endpoint, supplying a malicious file (e.g., a PHP web shell) without any authentication or file-type enforcement. The changed scope (S:C) in the CVSS vector indicates that successful exploitation can impact resources beyond the vulnerable component itself, such as the underlying web server and operating system. A public proof-of-concept exploit is available on GitHub (GitHub PoC, Patchstack).
Successful exploitation enables unauthenticated remote code execution on the affected WordPress server, giving attackers full control over the web application and potentially the underlying host. Attackers can exfiltrate sensitive data (customer records, credentials, payment information), modify site content, install persistent backdoors, and pivot to other systems on the same network. The vulnerability affects confidentiality, integrity, and availability at a HIGH level, with scope change indicating impact beyond the WordPress application boundary (Patchstack, Red Hat CVE).
A public proof-of-concept exploit was published on GitHub on March 19, 2026, lowering the barrier for exploitation (GitHub PoC). Patchstack has flagged this vulnerability as "Known to be Exploited" (KEV) and notes it is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity (Patchstack). No authentication or user interaction is required, making it trivially exploitable over the network. The EPSS score is approximately 0.043% (0.000430), and no specific threat actor attribution has been reported at this time.
inurl:woocommerce-wholesale-lead-capture).shell.php) containing code such as <?php system($_GET['cmd']); ?> that will execute arbitrary OS commands when accessed.wp-content/uploads/ or a plugin-specific subdirectory) by referencing the server response or using directory enumeration.https://target.com/wp-content/uploads/shell.php?cmd=id) to execute arbitrary commands on the server, enabling data exfiltration, privilege escalation, or installation of persistent backdoors (GitHub PoC, Patchstack)..php, .phtml, .php5, or other executable script files in WordPress upload directories (e.g., wp-content/uploads/); newly created files with randomized or suspicious names in plugin directories; web shell files containing functions like system(), exec(), passthru(), or base64_decode()..php files in upload directories; repeated requests from the same IP to the lead capture form endpoint.bash, curl, wget, python, or nc); unexpected outbound network connections initiated by the web server user account.The vendor has released a patched version: update to WooCommerce Wholesale Lead Capture version 2.0.3.2 or later immediately (Patchstack). If immediate updating is not possible, consider the following interim mitigations:
Patchstack, which discovered and disclosed the vulnerability, classified it as high priority and flagged it as "Known to be Exploited," warning of potential mass-exploit campaigns against WordPress sites (Patchstack). The vulnerability received coverage from The Hacker Wire and was discussed on social platforms including Mastodon and Bluesky shortly after the NVD publication (Wordfence Blog). The availability of a public GitHub PoC within days of disclosure amplified community concern about rapid weaponization.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."