Cybersecurity · 2 views
Hackers target WordPress sites via third-party WooCommerce plugin
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. The flaw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older.
AI Summary
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress, allowing them to upload a PHP backdoor. The flaw, tracked as CVE‑2026‑27540, affects plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file‑upload vulnerability discovered by security researcher Teemu Saarentaus. This exploitation targets WordPress sites that use the third‑party WooCommerce plugin.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks DataContinue reading
- BambooToken malware controls Windows and Linux systems via MQTTContinue reading
- What Zero-Day Response Should Be in the Post-Mythos EraContinue reading
- Thai Broadband Provider Hacked via Fortinet VulnerabilityContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow