Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin Under Active Exploitation

A critical unauthenticated file upload vulnerability in the WooCommerce Wholesale Lead Capture plugin is being actively exploited, with over 100,000 attack attempts blocked. The flaw allows attackers to upload PHP backdoors and achieve remote code execution. Patched version 2.0.3.2 is available. Update immediately.

Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin Under Active Exploitation

A critical security vulnerability in the WooCommerce Wholesale Lead Capture plugin is being actively exploited by attackers, with over 100,000 exploit attempts already blocked by the Wordfence firewall. This premium plugin, used by an estimated 6,000 active installations, provides a custom wholesale registration form with support for file upload fields.

If your WooCommerce store uses this plugin, this is an urgent alert you cannot afford to ignore.

Understanding the Vulnerability

The vulnerability, tracked as CVE-2026-27540, is an Unauthenticated Arbitrary File Upload flaw with a critical CVSS score of 9.8. It allows unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution on vulnerable sites.

How the Attack Works

The flaw exists in the plugin’s wwlc_file_upload_handler AJAX action, which is reachable by unauthenticated visitors. The handler is supposed to check uploaded file extensions against a list of allowed file types. However, in vulnerable versions (2.0.3.1 and earlier), that list is read directly from the request rather than from the form’s server-side configuration.

Because the check relies on this attacker-controlled value, an unauthenticated attacker can simply include “php” in their own list of allowed file types to bypass the restriction and upload a file with a .php extension.

The result: Attackers can write a PHP webshell to your site and execute arbitrary code, potentially creating administrator accounts, exfiltrating data, or taking complete control of your store.

The Attack Request in Action

Wordfence’s threat intelligence captured actual exploit attempts. Attackers submit a POST request to /wp-admin/admin-ajax.php with the action parameter set to wwlc_file_upload_handler, containing a forged file_settings parameter and a malicious file with a .php extension.

The forged file_settings parameter includes:

{"allowed_file_types": ["php", "jpg"], "max_allowed_file_size": 99999999}

The uploaded shell.php is a PHP webshell that reports host details and provides a browser-based upload form for writing additional malicious files.

Attack Data: A Sustained Campaign

Wordfence’s data reveals that attackers have been targeting this vulnerability for months, with significant exploit activity observed between June 4th and June 17th, as well as on July 1st and August 30th.

Top Offending IP Addresses

The following IP addresses are currently the most actively engaged in targeting this vulnerability:

IP AddressBlocked Requests
92.241.13.213Over 24,900
31.59.129.150Over 24,000
2a0f:85c1:840:5389::1Over 16,000
92.241.13.140Over 9,100
23.137.105.214Over 6,700
23.180.120.140Over 6,600
104.194.9.138Over 6,100
187.75.114.36Over 470
114.10.43.203Over 310
37.114.144.209Over 310

Are You at Risk?

Your site is vulnerable if:

  • You are running WooCommerce Wholesale Lead Capture version 2.0.3.1 or earlier
  • The plugin is active on your WordPress site

The good news: The plugin developer released a patched version (2.0.3.2) on February 20, 2026.

What You Must Do Now

1. Update the Plugin Immediately

The single most critical action is to update WooCommerce Wholesale Lead Capture to version 2.0.3.2 or later.

To update:

  • Log in to your WordPress dashboard
  • Navigate to Plugins → Installed Plugins
  • Find “WooCommerce Wholesale Lead Capture” and click “Update Now”

2. Check for Indicators of Compromise

A successful attack results in an executable PHP file being written to your server. We strongly recommend reviewing your site for any unexpected or recently created .php files, particularly within the uploads directory.

In observed attacks, uploaded files were often named shell.php, though attackers may use other filenames.

Also review your web server access logs for requests to /wp-admin/admin-ajax.php with the action parameter set to wwlc_file_upload_handler, especially those originating from the IP addresses listed above.

3. Enable a Web Application Firewall

Wordfence Premium, Care, and Response users received a firewall rule to protect against known exploits on February 27, 2026. Sites using the free version of Wordfence received the same protection on March 29, 2026.

If you use Wordfence, ensure your firewall is active and your rules are up to date. If you use a different security solution, verify that it provides equivalent protection.

4. Consider Professional Security Monitoring

As Wordfence notes, “the absence of any such log entries does not guarantee that your website has not been compromised”. Professional monitoring provides the visibility and expertise needed to detect and respond to threats that automated tools might miss.

The Broader Lesson: WooCommerce Security Requires Vigilance

This vulnerability is a stark reminder that e-commerce security is not a one-time setup; it is an ongoing discipline. WooCommerce stores are high-value targets because they process payments and store customer data.

At BG Cyber Connect, we have extensive experience securing WordPress and WooCommerce sites for Caribbean businesses. We have previously covered critical vulnerabilities in other widely used plugins, including the UpdraftPlus authentication bypass and the All-in-One WP Migration SQL injection.

For a deeper dive into protecting your online store, we recommend reviewing WooCommerce’s official security guide and their security best practices for auditing users, REST API keys, and traffic logs.

How BG Cyber Connect Can Help

At BG Cyber Connect, we understand that keeping your WordPress site secure requires constant vigilance. Our team can:

  • Perform an immediate security audit to verify your WooCommerce Wholesale Lead Capture version and identify any other vulnerabilities
  • Review your site for indicators of compromise and remediate any infections
  • Implement proactive security monitoring, including Web Application Firewall (WAF) protection
  • Provide ongoing patch management to ensure critical updates are applied promptly

If you are unsure whether your site has been compromised or need assistance securing your WordPress installation, contact us immediately.

The Bottom Line

Update WooCommerce Wholesale Lead Capture to version 2.0.3.2 now. Over 100,000 exploit attempts have already been blocked, and attackers have been targeting this vulnerability for months. Every day you delay increases the risk of a complete site takeover.

Need Help Securing Your WordPress Site?

Contact BG Cyber Connect for an Immediate Security Assessment

Explore our comprehensive WordPress security services:
BGCC Cybersecurity Solutions

Schedule Appointment

Book Now!