CVE-2026-27540: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-27540 is an Unrestricted File Upload vulnerability (CWE-434) in the WooCommerce Wholesale Lead Capture plugin by Rymera Web Co Pty Ltd, affecting all versions through 2.0.3.1. The flaw allows unauthenticated remote attackers to upload malicious files — including web shells and backdoors — to vulnerable WordPress installations. It was discovered and reported by Teemu Saarentaus and published by Patchstack on February 20, 2026, with NVD publication on March 19, 2026. The vulnerability carries a CVSS v3.1 base score of 9.0 (Critical) (Patchstack, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-434 (Unrestricted Upload of File with Dangerous Type), meaning the plugin fails to properly validate or restrict the file types accepted through its lead capture upload functionality. An unauthenticated attacker can submit a crafted HTTP request to the plugin's file upload endpoint, supplying a malicious file (e.g., a PHP web shell) without any authentication or file-type enforcement. The changed scope (S:C) in the CVSS vector indicates that successful exploitation can impact resources beyond the vulnerable component itself, such as the underlying web server and operating system. A public proof-of-concept exploit is available on GitHub (GitHub PoC, Patchstack).

Impact

Successful exploitation enables unauthenticated remote code execution on the affected WordPress server, giving attackers full control over the web application and potentially the underlying host. Attackers can exfiltrate sensitive data (customer records, credentials, payment information), modify site content, install persistent backdoors, and pivot to other systems on the same network. The vulnerability affects confidentiality, integrity, and availability at a HIGH level, with scope change indicating impact beyond the WordPress application boundary (Patchstack, Red Hat CVE).

Exploitability

A public proof-of-concept exploit was published on GitHub on March 19, 2026, lowering the barrier for exploitation (GitHub PoC). Patchstack has flagged this vulnerability as "Known to be Exploited" (KEV) and notes it is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity (Patchstack). No authentication or user interaction is required, making it trivially exploitable over the network. The EPSS score is approximately 0.043% (0.000430), and no specific threat actor attribution has been reported at this time.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WooCommerce Wholesale Lead Capture plugin (versions ≤ 2.0.3.1) using tools like WPScan, Shodan, or Google dorks (e.g., inurl:woocommerce-wholesale-lead-capture).
  2. Locate the upload endpoint: Navigate to or identify the plugin's lead capture form endpoint that accepts file uploads — typically accessible without authentication as part of the wholesale registration/lead capture workflow.
  3. Craft malicious payload: Prepare a PHP web shell file (e.g., shell.php) containing code such as <?php system($_GET['cmd']); ?> that will execute arbitrary OS commands when accessed.
  4. Upload the malicious file: Submit an HTTP POST request to the vulnerable upload endpoint with the PHP web shell as the file attachment, bypassing any client-side or server-side file type restrictions due to the lack of validation.
  5. Locate the uploaded file: Determine the upload directory path (commonly wp-content/uploads/ or a plugin-specific subdirectory) by referencing the server response or using directory enumeration.
  6. Execute remote code: Access the uploaded web shell via HTTP (e.g., https://target.com/wp-content/uploads/shell.php?cmd=id) to execute arbitrary commands on the server, enabling data exfiltration, privilege escalation, or installation of persistent backdoors (GitHub PoC, Patchstack).

Indicators of compromise

  • Network: Unexpected HTTP POST requests to the WooCommerce Wholesale Lead Capture plugin's file upload endpoint from unknown or suspicious IP addresses; outbound connections from the web server to external IPs following file upload activity.
  • File System: Presence of .php, .phtml, .php5, or other executable script files in WordPress upload directories (e.g., wp-content/uploads/); newly created files with randomized or suspicious names in plugin directories; web shell files containing functions like system(), exec(), passthru(), or base64_decode().
  • Logs: Web server access logs showing POST requests to the plugin's upload handler followed by GET requests to the same uploaded file path; HTTP 200 responses to requests for .php files in upload directories; repeated requests from the same IP to the lead capture form endpoint.
  • Process: Unusual child processes spawned by the web server process (e.g., Apache/Nginx spawning bash, curl, wget, python, or nc); unexpected outbound network connections initiated by the web server user account.

Mitigation and workarounds

The vendor has released a patched version: update to WooCommerce Wholesale Lead Capture version 2.0.3.2 or later immediately (Patchstack). If immediate updating is not possible, consider the following interim mitigations:

  • Disable the WooCommerce Wholesale Lead Capture plugin until patching is feasible.
  • Configure the web server to deny execution of scripts (PHP, etc.) in the WordPress uploads directory.
  • Implement a Web Application Firewall (WAF) rule to block malicious file uploads — Patchstack has issued a virtual patching/mitigation rule for its users.
  • Restrict file upload functionality to only necessary file types at the server level and review existing uploaded files for malicious content.

Community reactions

Patchstack, which discovered and disclosed the vulnerability, classified it as high priority and flagged it as "Known to be Exploited," warning of potential mass-exploit campaigns against WordPress sites (Patchstack). The vulnerability received coverage from The Hacker Wire and was discussed on social platforms including Mastodon and Bluesky shortly after the NVD publication (Wordfence Blog). The availability of a public GitHub PoC within days of disclosure amplified community concern about rapid weaponization.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management