Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
A high-severity security advisory was published regarding WooCommerce Wholesale Lead Capture.
Tracked as CVE-2026-27540 with a CVSS severity score of N/A/10.
Executive Threat Summary
On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution.
The post Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin appeared first on Wordfence.
This security vulnerability presents a direct risk of unauthorized data access, arbitrary script injection, or remote site compromise if left unaddressed. Because threat actors scan the internet automatically within hours of vulnerability disclosures, affected sites must be audited immediately.
Action Plan for Website Owners
- Check Your Installed Version: Verify what version of WooCommerce Wholesale Lead Capture is running in your WordPress admin dashboard (Plugins → Installed Plugins).
- Apply Patches Immediately: If a newer release is available, backup your database and update the software without delay.
- Inspect for Indicators of Attack: If your site cannot be updated immediately, check for unexpected administrative accounts or unusual traffic spikes.
- Get an Infrastructure Audit: Submit a rescue or security inquiry with Delvok. We verify server integrity and migrate your site to an isolated container environment.