Critical Vulnerability in WooCommerce Plugin Allows Hackers to Upload Malicious Code
AI-generated from multiple sources. Verify before acting on this reporting.
Global e-commerce sites running a specific premium WordPress plugin face an immediate threat after hackers exploited a critical security flaw to upload malicious code and seize control of websites. The vulnerability, identified as CVE-2026-27540, affects the WooCommerce Wholesale Lead Capture plugin, allowing attackers to bypass authentication and execute arbitrary file uploads without user interaction.
Security researcher Teemu Saarentaus discovered the defect, which enables unauthorized users to upload PHP backdoors directly onto infected servers. Once a malicious file is uploaded, attackers can execute code remotely, granting them complete administrative access to the compromised site. The flaw stems from insufficient input validation within the plugin's file-handling functions, creating an unauthenticated entry point for exploitation.
Defiant, the security firm that maintains the Wordfence brand, confirmed the severity of the issue and is coordinating with developers to address the breach. The vulnerability impacts sites worldwide that utilize the premium version of the WooCommerce Wholesale Lead Capture tool, a popular extension used by businesses to manage wholesale customer data and lead generation. Because the exploit requires no login credentials, any site running the vulnerable software is at risk regardless of its security posture.
The attack vector has been active since early September 2026. Cybercriminals have leveraged the flaw to install webshells, which serve as persistent access points for further malicious activities, including data theft, ransomware deployment, and redirection to phishing sites. The widespread nature of WordPress and WooCommerce plugins means that thousands of online stores could be affected if they have not yet applied patches or removed the compromised software.
WordPress site administrators are urged to update the plugin immediately or disable it until a secure version is available. Developers for the plugin have acknowledged the report and are working on an emergency patch. However, the timeline for a full resolution remains unclear as security teams assess the extent of the damage across the global network of affected sites.
Questions remain regarding the number of sites already compromised and whether attackers have used the backdoors to exfiltrate sensitive customer data or financial information. Security experts warn that even after patching, administrators must scan their systems for lingering malware and change all administrative passwords to ensure the threat is fully neutralized. The incident highlights the ongoing risks posed by third-party extensions in the open-source ecosystem, where a single vulnerability can cascade into a global security crisis.