Hackers target WordPress sites via third-party WooCommerce plugin | HappeningNow.news

Cybersecurity · 2 views

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. The flaw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older.

Source AI Summary Published 1h 10m ago Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 2 Community interest
Brief read Under 1 min brief 59 words

AI Summary

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress, allowing them to upload a PHP backdoor. The flaw, tracked as CVE‑2026‑27540, affects plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file‑upload vulnerability discovered by security researcher Teemu Saarentaus. This exploitation targets WordPress sites that use the third‑party WooCommerce plugin.

AI summaries can be wrong sometimes—always verify important details using the source article.

How AI & Automation are used
Read original at Bleepingcomputer

Coverage Context

Part of Woocommerce coverage 3 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page