Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WooCommerce Vulnerability Exploited by Attackers

Critical WooCommerce Vulnerability Exploited by Attackers

Posted on September 16, 2026 By CWS

Attackers are actively targeting a significant security flaw in the WooCommerce Wholesale Lead Capture plugin, a widely used premium plugin on WordPress, currently installed on over 6,000 websites. Wordfence, a prominent WordPress security firm, revealed that this vulnerability allows unauthorized users to upload arbitrary files, including PHP backdoors, enabling remote code execution. This vulnerability, identified as CVE-2026-27540 with a CVSS score of 9.8, has led to over 100,000 blocked exploit attempts since June 2026, with 99 attempts recorded just in the past 24 hours.

Understanding the WooCommerce Vulnerability

This vulnerability stems from the lack of file type validation in the ‘wwlc_file_upload_handler’ AJAX action of the plugin, affecting all versions up to and including 2.0.3.1. This flaw allows attackers to upload malicious files to the server of the affected site, leading to potential remote code execution. During observed attacks, threat actors have been using the ‘wwlc_file_upload_handler’ AJAX action to send crafted requests with a malicious PHP file, identified as ‘shell.php’.

This uploaded PHP file serves as a web shell, providing attackers with system details and a user interface for uploading additional malicious files. Wordfence has identified several IP addresses from which these attack attempts have been launched, suggesting a coordinated effort to exploit this vulnerability.

Preventive Measures for WordPress Site Owners

Due to the serious nature of this vulnerability, WordPress site owners using the WooCommerce Wholesale Lead Capture plugin are advised to vigilantly check for unexpected or newly created .php files, especially in the uploads directory. Additionally, they should scrutinize any suspicious requests to ‘/wp-admin/admin-ajax.php’ with the action parameter set to ‘wwlc_file_upload_handler’, originating from the identified IP addresses. Prompt action can mitigate the risks of having their sites compromised.

Related Vulnerabilities in The Events Calendar Plugin

In a related development, Wordfence reported critical flaws in The Events Calendar plugin, installed on over 600,000 sites. These vulnerabilities, tracked as CVE-2026-78159 and CVE-2026-78006, both with a CVSS score of 9.8, arise from insufficient validation and protection mechanisms. Exploiting these flaws allows attackers to execute remote code without authentication, potentially taking over the site. The vulnerabilities have been addressed in the latest plugin updates, versions 6.17.3.1 and 6.17.4.1.

Wordfence highlighted that these vulnerabilities could be exploited through WordPress’s pending-comment preview, leading to complete site control, data theft, and malware installation. Users of The Events Calendar plugin are strongly urged to update to the latest versions to protect their sites from these threats.

In conclusion, these incidents underscore the critical importance of maintaining updated plugins and being vigilant about security advisories to safeguard WordPress sites against emerging threats.

The Hacker News Tags:CVE-2026-27540, cyber threat, PHP shell, plugin vulnerability, remote code execution, security flaw, security patch, site protection, vulnerability management, web security, web shell, WooCommerce, Wordfence, WordPress plugin, WordPress security

Post navigation

Previous Post: Chrome 153 Update Addresses Critical Security Flaws
Next Post: Critical WSO2 API Manager Vulnerability Exploited

Related Posts

AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain Attacks The Hacker News
Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data Researchers Find Malicious VS Code, Go, npm, and Rust Packages Stealing Developer Data The Hacker News
CISA Identifies Critical Flaws in ConnectWise and Windows CISA Identifies Critical Flaws in ConnectWise and Windows The Hacker News
WhatsApp Attack Uses Fake Files to Deploy RMM Software WhatsApp Attack Uses Fake Files to Deploy RMM Software The Hacker News
Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms Qilin Ransomware Adds “Call Lawyer” Feature to Pressure Victims for Larger Ransoms The Hacker News
AI Model Uncovers 10,000 Critical Software Flaws AI Model Uncovers 10,000 Critical Software Flaws The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical WSO2 API Manager Vulnerability Exploited
  • Critical WooCommerce Vulnerability Exploited by Attackers
  • Chrome 153 Update Addresses Critical Security Flaws
  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical WSO2 API Manager Vulnerability Exploited
  • Critical WooCommerce Vulnerability Exploited by Attackers
  • Chrome 153 Update Addresses Critical Security Flaws
  • Critical cPanel Security Flaw in LiteSpeed Server Fixed
  • Homebrew 7.0.0 Unveils Vulnerability Scanner and Enhanced Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark