NewsTradingSentimentCalendarCommunityBriefing
Tech

WooCommerce Plugin Flaw Allows Remote Site Takeover

By Tech Desk · 2026-09-16 · 3 min read
A digital padlock hanging from a chain against a dark background
Illustration: Tradingbird

A critical security gap in a popular e-commerce add-on is being actively exploited to install malicious code on WordPress sites, with over 100,000 attack attempts blocked since June.

Cybercriminals are actively exploiting a critical vulnerability in WooCommerce Wholesale Lead Capture, a premium WordPress plugin used by more than 6,000 active installations. The flaw allows unauthenticated attackers to upload arbitrary files to the server, effectively granting them full control over the website without needing any login credentials. This is not a theoretical risk; security firm Wordfence reports having blocked over 100,000 exploit attempts targeting this specific weakness since June 2026, with a significant spike of 99 attempts recorded in the last 24 hours alone.

The vulnerability, tracked as CVE-2026-27540 with a maximum severity score of 9.8, stems from a lack of proper file type validation in a specific internal function. This missing check creates a direct pathway for remote code execution. While the plugin is designed to help businesses capture wholesale leads, the security gap undermines its entire purpose by exposing the server to unauthorized manipulation. Site owners are advised to immediately check for unexpected PHP files in their uploads directories, as this is the primary indicator of a successful compromise.

Web Shells Enable Persistent Access

The observed attacks involve threat actors submitting crafted requests to a specific internal action to upload a malicious file named shell.php. This file acts as a web shell, a backdoor that allows attackers to maintain persistent access to the compromised server. Once installed, the shell can report host details and provide a browser-based interface for uploading additional malicious tools. The attack attempts have originated from a specific set of IP addresses, which have been identified by security researchers. The presence of such a shell means that even if the vulnerability is patched, the attacker may already have a foothold to continue stealing data or deploying further malware.

For site administrators, the trade-off of using this specific lead capture functionality is now a heightened security risk if the plugin is not updated. The flaw affects all versions up to and including 2.0.3.1. Wordfence advises reviewing server logs for suspicious requests to the admin-ajax endpoint with the specific action parameter used in the exploit. This is a clear case where a minor convenience feature in a plugin introduced a severe vulnerability that is now being weaponized at scale. The urgency is high, as the attack vector requires no authentication, making it an easy target for automated bots.

Parallel Flaws Hit Events Calendar Plugin

This incident occurs alongside the discovery of two other critical flaws in The Events Calendar, a widely used plugin installed on over 600,000 websites. These vulnerabilities, both scoring 9.8 on the CVSS scale, also allow for unauthenticated remote code execution. The attacks exploit insufficient validation in the plugin's widget-rendering pipeline. Unlike the lead capture flaw, these attacks require the target event page to have comments enabled and a specific option for showing comments on event pages to be active.

The exploitation chains for The Events Calendar are complex, involving PHP object injection to execute arbitrary operating system commands or bypassing security guards to reset administrator passwords. Once an attacker gains this level of access, they can upload malicious plugins to take complete control of the site. StellarWP, the developer of the plugin, has released patches in versions 6.17.3.1 and 6.17.4.1 to address these issues. However, the attack can be triggered through WordPress's pending-comment preview feature without moderator approval, making it a particularly dangerous vector for automated attacks. Site owners should verify their comment settings and update immediately.

Security Implications For Site Owners

The combination of these vulnerabilities highlights a recurring theme in the WordPress ecosystem: third-party plugins can introduce severe security risks if they do not rigorously validate user input. The WooCommerce Wholesale Lead Capture flaw is particularly concerning because it affects a feature that is often left enabled by default. The active exploitation reported by The Hacker News underscores the need for immediate action. Site owners should not wait for a confirmed breach to act. Updating plugins, reviewing file integrity, and monitoring server logs are essential steps to mitigate the risk of remote code execution. The cost of inaction could be the loss of customer data and complete site takeover.

Based on reporting by The Hacker News, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories
  • A fantasy lighthouse standing on a rocky cliff overlooking a calm sea
    Illustration: Tradingbird

    Trails in the Sky 2nd Chapter Remake Delivers on Its Promises

    Nihon Falcom’s latest release continues the story of Liberl with deeper quests and improved character dynamics, though it remains a safe choice for fans of the genre.

    2026-09-16
  • A modern office desk with a laptop and a coffee cup
    Illustration: Tradingbird

    Millennials Dominate High-Paying AI Roles Amid Gender Gap

    New data reveals that workers aged 30 to 45 are securing the majority of senior artificial intelligence positions with six-figure salaries. However, this financial windfall is not evenly distributed, with significant disparities in gender and educational background persisting across the industry.

    2026-09-16
  • A human hand reaching out to touch a glowing, translucent sphere of light
    Illustration: Tradingbird

    Survey Reveals Deep Anxiety over AI's Impact on Human Agency

    While adoption of AI tools remains high, a new study shows a significant portion of Americans fear losing their ability to think critically and maintain personal purpose.

    2026-09-16