THREATOPS
THREAT OPSThreat News › CVE-2026-27540 WooCommerce Flaw Exploited

CVE-2026-27540 WooCommerce Flaw Exploited

medsocradar_blogPublished 2026-09-16

<h1>CVE-2026-27540 WooCommerce Flaw Exploited</h1> <p>Attackers are actively exploiting <strong>CVE-2026-27540</strong>, a critical arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin for WordPress.</p> <p>The flaw allows unauthenticated attackers to upload arbitrary files to affected servers, potentially leading to <a href="https://socradar.io/glossary/remote-code

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://socradar.io/blog/cve-2026-27540-woocommerce-flaw/