Unrestricted File Upload Vulnerability in Woocommerce Wholesale Lead Capture by Rymera Web Co
CVE-2026-27540

9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 March 2026

Badges

๐Ÿ”ฅ Trending now๐Ÿ“ˆ Trended๐Ÿ“ˆ Score: 2,400๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2026-27540?

CVE-2026-27540 is a critical vulnerability found in the Woocommerce Wholesale Lead Capture plugin, developed by Rymera Web Co. This plugin is designed for WooCommerce, a popular WordPress e-commerce platform, enabling online merchants to manage wholesale leads and streamline customer engagement. The vulnerability allows for an unrestricted file upload of dangerous types, meaning attackers can exploit this flaw to upload malicious files. Such capabilities can lead to severe ramifications for organizations, including unauthorized execution of code on the web server and potential compromise of sensitive customer data. This vulnerability affects versions of the plugin up to and including 2.0.3.1, leaving many e-commerce sites at risk if they are not promptly updated.

Potential impact of CVE-2026-27540

  1. Unauthorized Access and Control: Attackers can upload harmful files, leading to remote code execution. This unauthorized access can enable them to take control of affected websites, manipulate content, or execute further malicious actions.

  2. Data Breach Risks: The ability to upload dangerous files could facilitate the extraction of sensitive customer data, resulting in significant privacy issues and compliance violations, especially for businesses handling user information.

  3. Reputation Damage and Financial Loss: Exploiting this vulnerability can lead to downtime, loss of customer trust, and significant financial repercussions due to potential legal actions or data recovery efforts, which can ultimately impact the organizationโ€™s reputation in the market.

Affected Version(s)

Woocommerce Wholesale Lead Capture 0 <= 2.0.3.1

News Articles

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Attackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells and gain remote code execution.

3 days ago

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • ๐Ÿ“ˆ

    Vulnerability started trending

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by The Hacker News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Teemu Saarentaus | Patchstack Bug Bounty Program
.