Unrestricted File Upload Vulnerability in Woocommerce Wholesale Lead Capture by Rymera Web Co
CVE-2026-27540
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 19 March 2026
Badges
What is CVE-2026-27540?
CVE-2026-27540 is a critical vulnerability found in the Woocommerce Wholesale Lead Capture plugin, developed by Rymera Web Co. This plugin is designed for WooCommerce, a popular WordPress e-commerce platform, enabling online merchants to manage wholesale leads and streamline customer engagement. The vulnerability allows for an unrestricted file upload of dangerous types, meaning attackers can exploit this flaw to upload malicious files. Such capabilities can lead to severe ramifications for organizations, including unauthorized execution of code on the web server and potential compromise of sensitive customer data. This vulnerability affects versions of the plugin up to and including 2.0.3.1, leaving many e-commerce sites at risk if they are not promptly updated.
Potential impact of CVE-2026-27540
-
Unauthorized Access and Control: Attackers can upload harmful files, leading to remote code execution. This unauthorized access can enable them to take control of affected websites, manipulate content, or execute further malicious actions.
-
Data Breach Risks: The ability to upload dangerous files could facilitate the extraction of sensitive customer data, resulting in significant privacy issues and compliance violations, especially for businesses handling user information.
-
Reputation Damage and Financial Loss: Exploiting this vulnerability can lead to downtime, loss of customer trust, and significant financial repercussions due to potential legal actions or data recovery efforts, which can ultimately impact the organizationโs reputation in the market.
Affected Version(s)
Woocommerce Wholesale Lead Capture 0 <= 2.0.3.1
News Articles
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Attackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells and gain remote code execution.
3 days ago
References
CVSS V3.1
Timeline
- ๐
Vulnerability started trending
- ๐พ
Exploit known to exist
- ๐ฐ
First article discovered by The Hacker News
Vulnerability published
Vulnerability Reserved