Our takeHackers are exploiting CVE-2026-27540 in the WooCommerce Wholesale Lead Capture plugin (≤2.0.3) to upload PHP backdoors. Update to a fixed version now if you run it.Cyber Resilience desk
What this means for you — Security leader:If you run WooCommerce Wholesale Lead Capture v2.0.3 or earlier on any WordPress site, update immediately to a fixed version; the CVE-2026-27540 unauthenticated arbitrary file upload is under active exploitation.
What this means for you — Lean IT orgs:If your online store uses the WooCommerce Wholesale Lead Capture plugin, check the version today and update it right away; attackers are using a known flaw to upload backdoors on these sites.
What this means for you — MSP:Audit all managed WordPress/WooCommerce instances for the Wholesale Lead Capture plugin; versions 2.0.3 and below are under active exploitation via CVE-2026-27540 and should be updated immediately.
What this means for you — Researcher:CVE-2026-27540 in the WooCommerce Wholesale Lead Capture plugin (≤2.0.3) is under active exploitation for unauthenticated PHP backdoor upload; monitor for related IoCs on affected WordPress sites.