{"id":1730,"date":"2026-09-17T12:10:30","date_gmt":"2026-09-17T06:40:30","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1730"},"modified":"2026-09-18T11:08:08","modified_gmt":"2026-09-18T05:38:08","slug":"cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/","title":{"rendered":"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin"},"content":{"rendered":"<p>Attackers are actively exploiting CVE-2026-27540, a critical WooCommerce plugin <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-vulnerability-management\/\">vulnerability<\/a> in WooCommerce Wholesale Lead Capture. The flaw lets unauthenticated attackers upload files with any extension to a vulnerable WordPress site. Security researcher Teemu Saarentaus discovered the arbitrary file upload issue, which affects plugin versions 2.0.3.1 and earlier.<\/p>\n<p>Once inside, attackers drop a PHP web shell to run reconnaissance, harvest host details, and stage further payloads. Wordfence has blocked more than<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=cve_2026_27540\" target=\"_blank\" rel=\"nofollow noopener\"> 100,000<\/a> exploitation attempts tied to this WordPress web shell campaign since June 2026.<\/p>\n<p>This matters for any organization running WooCommerce for ecommerce, wholesale, or lead-generation workflows. A single unpatched plugin can hand attackers a foothold inside business-critical infrastructure.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>How the exploit works<\/h2>\n<p>The wwlc_file_upload_handler AJAX action normally checks uploaded files against an allowlist of permitted extensions. That allowlist comes from a file_settings parameter that the request itself supplies, not from a server-side setting. An attacker simply adds &#8220;php&#8221; to the permitted list and submits a crafted upload request.<\/p>\n<p>The plugin then accepts the file. Wordfence documented the resulting payload as shell.php, a PHP web shell with specific functions:<\/p>\n<ul>\n<li>Reports host and server details back to the attacker<\/li>\n<li>Provides a browser-based form for writing additional files to the site<\/li>\n<li>Enables follow-on reconnaissance and payload deployment<\/li>\n<\/ul>\n<p>Vulnerability trackers classify the flaw as CWE-434, unrestricted upload of a file with a dangerous type. Severity ratings vary by source. Wordfence rates it 9.8, while the <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-common-vulnerabilities-and-exposures-cve-in-cybersecurity\/\">CVE<\/a> record from Patchstack lists 9.0, a gap that partly reflects differing views on attack complexity.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-essentials.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Cybersecurity essentials for any organization<\/h4><p>Guide to cybersecurity essentials, core functions, and organizational protection practices.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/cybersecurity-essentials-for-any-organization\/\" aria-label=\"Cybersecurity essentials for any organization\"><\/a><\/div><\/div><\/div>\n<h2>Scale and timing of attacks<\/h2>\n<p>Rymera Web Co, the plugin vendor, patched the vulnerability in version 2.0.3.2 on February 20, 2026. Exploitation did not stop after the patch shipped. Wordfence reported exploitation spikes between June 4 and June 17, and again on July 1 and August 30.<\/p>\n<p>The plugin has an estimated 6,000 active installations. Any site still running version 2.0.3.1 or earlier remains exposed to unauthenticated file upload attacks.<\/p>\n<h2>Indicators of compromise<\/h2>\n<table style=\"width: 100%; height: 144px;\">\n<thead>\n<tr style=\"height: 24px;\">\n<th style=\"width: 31.0782%; text-align: left; height: 24px;\"><strong>Indicator<\/strong><\/th>\n<th style=\"width: 30.1269%; text-align: left; height: 24px;\"><strong>Where to Check<\/strong><\/th>\n<th style=\"width: 37.7378%; text-align: left; height: 24px;\"><strong>Recommended Action<\/strong><\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"height: 24px;\">\n<td style=\"width: 31.0782%; height: 24px;\">Unexpected PHP files (e.g., shell.php)<\/td>\n<td style=\"width: 30.1269%; height: 24px;\">Plugin upload directories<\/td>\n<td style=\"width: 37.7378%; height: 24px;\">Remove the file and investigate how it arrived<\/td>\n<\/tr>\n<tr style=\"height: 48px;\">\n<td style=\"width: 31.0782%; height: 48px;\">Requests invoking wwlc_file_upload_handler<\/td>\n<td style=\"width: 30.1269%; height: 48px;\">admin-ajax.php access logs<\/td>\n<td style=\"width: 37.7378%; height: 48px;\">Review source IPs and block confirmed malicious addresses<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 31.0782%; height: 24px;\">Unrecognized administrator accounts<\/td>\n<td style=\"width: 30.1269%; height: 24px;\">WordPress user list<\/td>\n<td style=\"width: 37.7378%; height: 24px;\">Remove the account and rotate admin credentials<\/td>\n<\/tr>\n<tr style=\"height: 24px;\">\n<td style=\"width: 31.0782%; height: 24px;\">Plugin version 2.0.3.1 or earlier<\/td>\n<td style=\"width: 30.1269%; height: 24px;\">Plugin settings page<\/td>\n<td style=\"width: 37.7378%; height: 24px;\">Update to version 2.0.3.2 or later immediately<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Why this matters beyond the plugin itself<\/h2>\n<p>WordPress and WooCommerce sites often support customer portals, marketing funnels, and lead-generation forms. A compromised public site can become infrastructure attackers reuse for other purposes:<\/p>\n<ul>\n<li>Staging additional <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-malware\/\">malware<\/a> or tools for later use<\/li>\n<li>Hosting <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-phishing\/\">phishing<\/a> pages under a trusted domain<\/li>\n<li>Harvesting credentials entered on the compromised site<\/li>\n<li>Serving as a pivot point toward connected business systems<\/li>\n<\/ul>\n<p>None of these outcomes are confirmed in the current reporting. They represent the general risk a web shell introduces once attackers gain a foothold, not a claim about what happened at any specific site.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp\" class=\"resource-box__image\" alt=\"cybersecurity kit\" loading=\"lazy\" srcset=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit-.jpg?format=webp 960w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--300x225.jpg?format=webp 300w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--768x576.jpg?format=webp 768w, https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/cybersecurity-kit--133x100.jpg?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"cybersecurity kit\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Cybersecurity kit\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Download this cybersecurity kit for blueprints, frameworks, checklists, policy templates, and UEM security guides today.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/resource-kits\/cybersecurity-kit\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>Containment and patch steps<\/h2>\n<ul>\n<li>Update WooCommerce Wholesale Lead Capture to version 2.0.3.2 or later without delay<\/li>\n<li>Search upload directories for recently created or unfamiliar PHP files<\/li>\n<li>Review admin-ajax.php logs for requests targeting wwlc_file_upload_handler<\/li>\n<li>Audit administrator accounts and remove any that were not provisioned by IT<\/li>\n<\/ul>\n<p>If compromise is confirmed, restore the site from a known-clean backup, since fully removing every persistence mechanism can be difficult to verify<\/p>\n<p>Plugin <a href=\"https:\/\/www.hexnode.com\/blogs\/what-is-patch-management\/\">patch management<\/a> is separate from server or endpoint patching. Updating the WooCommerce plugin does not address vulnerabilities elsewhere in the hosting stack.<\/p>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Is CVE-2026-27540 still being actively exploited?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Yes. Wordfence has blocked over 100,000 attack attempts since June 2026, with activity spikes in June, July, and August.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">How can administrators tell if their site was compromised?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Check upload directories for unexpected PHP files and review admin-ajax.php logs for requests to wwlc_file_upload_handler. Also look for unrecognized administrator accounts.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should administrators do if they find a web shell?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Wordfence recommends restoring the site from a clean backup. Removing every persistence mechanism and backdoor account individually can be difficult to verify.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>CVE-2026-27540 shows how one unpatched WordPress plugin can expose an entire site to unauthenticated compromise. Organizations running WooCommerce Wholesale Lead Capture should update to version 2.0.3.2 or later and check for the indicators above.<\/p>\n<p>Plugin security deserves the same operational priority as any other internet-facing system. Delayed patching on a third-party plugin can carry the same consequences as delayed patching anywhere else.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay ahead of active plugin exploits. <\/h5><p>Get security briefings like this delivered to your inbox weekly. <\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Attackers are actively exploiting CVE-2026-27540, a critical WooCommerce plugin vulnerability in WooCommerce Wholesale Lead Capture&#8230;.<\/p>\n","protected":false},"author":5,"featured_media":1732,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15,21],"class_list":["post-1730","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-malware","category-patch-management","product_category-extended-detection-and-response","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin<\/title>\n<meta name=\"description\" content=\"Attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells. Patch to 2.0.3.2 and check for compromise.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin\" \/>\n<meta property=\"og:description\" content=\"Attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells. Patch to 2.0.3.2 and check for compromise.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-17T06:40:30+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-18T05:38:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-27540.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin\",\"datePublished\":\"2026-09-17T06:40:30+00:00\",\"dateModified\":\"2026-09-18T05:38:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/\"},\"wordCount\":806,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cve-2026-27540.jpeg?format=webp\",\"articleSection\":[\"Malware\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/\",\"name\":\"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cve-2026-27540.jpeg?format=webp\",\"datePublished\":\"2026-09-17T06:40:30+00:00\",\"dateModified\":\"2026-09-18T05:38:08+00:00\",\"description\":\"Attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells. Patch to 2.0.3.2 and check for compromise.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cve-2026-27540.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/cdn.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cve-2026-27540.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"cve 2026 27540\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"description\":\"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin","description":"Attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells. Patch to 2.0.3.2 and check for compromise.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/","og_locale":"en_US","og_type":"article","og_title":"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin","og_description":"Attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells. Patch to 2.0.3.2 and check for compromise.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-09-17T06:40:30+00:00","article_modified_time":"2026-09-18T05:38:08+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-27540.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin","datePublished":"2026-09-17T06:40:30+00:00","dateModified":"2026-09-18T05:38:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/"},"wordCount":806,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-27540.jpeg?format=webp","articleSection":["Malware","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/","url":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/","name":"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/#primaryimage"},"thumbnailUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-27540.jpeg?format=webp","datePublished":"2026-09-17T06:40:30+00:00","dateModified":"2026-09-18T05:38:08+00:00","description":"Attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells. Patch to 2.0.3.2 and check for compromise.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/#primaryimage","url":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-27540.jpeg?format=webp","contentUrl":"https:\/\/cdn.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/09\/cve-2026-27540.jpeg?format=webp","width":1340,"height":700,"caption":"cve 2026 27540"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/cve-2026-27540-active-exploits-hit-woocommerce-lead-plugin\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"CVE-2026-27540: Active Exploits Hit WooCommerce Lead Plugin"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"description":"A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions\u2014without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable\u2014politely.","url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1730","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1730"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1730\/revisions"}],"predecessor-version":[{"id":1739,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1730\/revisions\/1739"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1732"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1730"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1730"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}