Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Hackers exploit WordPress plugin flaw to upload PHP backdoors

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload PHP backdoors. Tracked as CVE-2026-27540, the flaw affects plugin versions 2.0.3.1 and older.

Security researcher Teemu Saarentaus discovered the unauthenticated arbitrary file-upload flaw. The exposed wwlc_file_upload_handler AJAX action checks file extensions using settings supplied in the user-controlled file_settings parameter. Attackers can add “php” to the permitted types, upload PHP webshells, and potentially take complete control of a site.

The issue was fixed in version 2.0.3.2, released on February 20. WordPress security company Defiant says its Wordfence web application firewall blocked over 100,000 attacks linked to the vulnerability. Wordfence reports that exploitation spiked between June 4 and June 17, and again on July 1 and August 30.

According to Wordfence, the uploaded webshell can collect host details and provide a browser-based form for writing additional malicious files. The company has identified IP addresses responsible for tens of thousands of attempts. Researchers recommend upgrading to version 2.0.3.2 or later and checking for unexpected PHP files, suspicious requests to /wp-admin/admin-ajax.php, and unknown administrator accounts. If compromise is confirmed, they say restoring the site from a safe backup may be necessary.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.