THREAT OPS › Threat News › CVE-2026-27540 WooCommerce Flaw Exploited
CVE-2026-27540 WooCommerce Flaw Exploited
<h1>CVE-2026-27540 WooCommerce Flaw Exploited</h1> <p>Attackers are actively exploiting <strong>CVE-2026-27540</strong>, a critical arbitrary file-upload vulnerability in the WooCommerce Wholesale Lead Capture plugin for WordPress.</p> <p>The flaw allows unauthenticated attackers to upload arbitrary files to affected servers, potentially leading to <a href="https://socradar.io/glossary/remote-code
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-27540cve
- https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/url
- 2.0.3.1ipv4
- 2.0.3.2ipv4
Original source: https://socradar.io/blog/cve-2026-27540-woocommerce-flaw/