Vulnerabilities & Exploits · Web App Attack

WooCommerce Plugin Exploits Plant WordPress Backdoors

BleepingComputer reports active exploitation of CVE-2026-27540 in the premium WooCommerce Wholesale Lead Capture plugin for WordPress, where attackers are using the flaw to upload a PHP backdoor to affected sites. The issue turns a trusted plugin path into a foothold on the server itself.

In plain terms, the plugin accepts something the site treats like a normal upload, and the uploaded PHP file can then execute as site code. That means the compromise is not limited to the original request: once the backdoor lands, the attacker can keep reaching the site until that file and any follow-on persistence are removed.

For WordPress installs that rely on third-party plugins or user uploads, the exposure sits at the site layer, not just the extension layer. Paid or niche plugins do not escape that trust problem, so a compromise here can still put the whole site, including admin sessions and customer data, under attacker control.

1 source · 10h ago

CVE-2026-27540

NVD KEV

CVSS 9 CRITICAL: unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. EPSS 2% (76th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-09-15

Every edition of this story: WooCommerce Plugin Exploits Plant WordPress Backdoors

More from today