Critical Vulnerability in WWLC (CVE-2026-27540) allows uploading files and running code

Author: Published 6 min de lectura 16 reading

The images in this article were generated with artificial intelligence. How we publish

Wordfence has warned that attackers are exploiting critical vulnerability in the premium WooCommerce Wholesale Lead Capture, which has over 6,000 active facilities, to upload arbitrary files - including PHP web shells - and get remote code execution on WordPress sites. According to the security firm, more than 100,000 attempts at exploitation since June 2026, with 99 attempts recorded in the last 24 hours; the failure is traced as CVE-2026-27540 (CVSS 9.8). In parallel, Wordfence described two critical exploitation chains against The Events Calendar (installed in hundreds of thousands of sites) that allow unauthenticated control; StellarWP already published patches for these failures. The pieces confirmed by public investigations tell us what happened, how it works technically, who are at risk and what concrete steps a site manager should take right now.

In technical terms, vulnerability in WooCommerce Wholesale Lead Capture is a condition of arbitrary uploading of files originated by the lack of file type validation in an AJAX action called "wwlc _ file _ upload _ handler." All versions up to 2.0.3.1 are affected, and attackers have been sending forged requests with a manipulated file _ settings parameter and a malicious PHP file (e.g. "shell.php"). The uploaded file acts as a web shell: it displays host information and provides a web interface to write or deploy more malicious files on the compromised server. Wordfence publishes technical details and recommendations in its public analysis; it can be consulted on its blog for more depth Wordfence Blog and the official vulnerability register appears in the NVD database CVE-2026-27540. The plugin page in the WordPress repository confirms the product concerned WooCommerce Wholesale Lead Capture.

Critical Vulnerability in WWLC (CVE-2026-27540) allows uploading files and running code
Image generated with IA.

Wordfence has identified operating requests originating from a series of IP addresses observed in its blocks (e.g. 92.241.13.213, 31.59.129.150, 23.137.105.214, among others, and IPv6 2a0f: 85c1: 840: 5389: 1). These indicators are used for rapid detection but do not guarantee attribution or completeness- attackers can rotate PIs, use proxys or third-party infrastructure - so relying only on blocking those PIs is not a complete defense.

At the same time, Wordfence described two exploitable chains in The Events Calendar with CVE-2026-78159 and CVE-2026-78006 (both CVSS 9.8) that start in the widget rendering pipeline and end up in remote execution without authentication. The first chain exploits insufficient validation in the management of 'classes' maps to achieve PHP Object Injection and run system commands; the second chain eludes protections and uses a primitive "arbitrary callable" to restore an administrator's password and then load a malicious plugin, achieving total site control. Both require that comments be enabled on the event page and that the "Show comments on event pages" option be active; in addition Wordfence warns that they can be activated through the preview of pending comments, which eliminates the need for prior moderation. StellarWP has published patches that correct these routes: update the correction versions indicated by the developer (the parcheed versions were published by StellarWP).

What this means for WordPress owners and administrators: any site that uses WooCommerce Wholesale Lead Capture in vulnerable version or The Events Calendar in pre-run versions is exposed to risks of web shells rise, command execution, credentials theft, back door installation and, in extreme cases, total site commitment. The operation does not require authentication in the described vectors, so the risk is immediate and high impact.

Specific and immediate measures to be implemented (confirmed by incident response practices and public recommendations): update priority. For The Events Calendar, apply the corrected versions published by StellarWP (see the developer's note and update the plugin to the above versions). For WooCommerce Wholesale Lead Capture, if there is already a parched version available by the supplier, update immediately; if no patch is publicly available, consider disabling or removing the plugin until there is an official correction. In parallel, implement WAF rules that block requests to / wp-admin / admin-ajax.php with the action parameter = wwlc _ file _ upload _ handler and restrict file uploading with executable extensions to the uploads directory.

Practical inspection steps if you manage a potentially affected site: review the upload directory by looking for unexpected .php files (for example with a find command on the server: find wp-content / uploads -type f -name '* .php' -printf '% T +% p\ n' ¬ 124; sort -r), check web and server access records for requests to / wp-admin / admin-ajax.php with action = wwlc _ file _ upload _ handler and examine timstamps and file owners. Look for unusual outgoing connection patterns and wp _ options inputs that can indicate active back doors. If you detect an intrusion, isolate the site (put it in maintenance or get it out of traffic), change secret administrative credentials and keys (leaps and authentication keys from WordPress), and coordinate with your hosting provider to perform a forensic analysis and restoration from a clean copy if necessary.

Critical Vulnerability in WWLC (CVE-2026-27540) allows uploading files and running code
Image generated with IA.

It is also convenient to scan with specialized security tools (Wordfence, Sucuri, Maldet, or the scanner of your choice) and review the list of installed plugins; if the immediate update is not possible, disable the vulnerable plugin and block access to admin-ajax.php for requests that do not come from trusted origins. Note that blocking only the PIs observed by Wordfence is a temporary measure: the attackers will change infrastructure, so software correction and web shells removal are essential.

Confirmed facts: the vulnerability of arbitrary rise in WooCommerce Wholesale Lead Capture (CVE-2026-27540), the operating patterns observed by Wordfence (including the use of a shell.php), the number of blocked attempts reported by Wordfence and the reported CVE for The Events Calendar along with the publication of patches by StellarWP. Untrue estimates and areas: the actual number of sites that have been successfully committed has not been published in an aggregate form by third parties and the attribution of attacks to a particular actor is not publicly confirmed. The practical recommendation is to act now: update, inspect and, if necessary, delete and restore from clean copies to remove any residual back door.

For additional reference and technical reading see official entries and notices: Wordfence analysis Wordfence Blog, the NVD record of the WooCommerce Wholesale Lead Capture CVE-2026-27540 and pages of affected plugins on WordPress.org ( WooCommerce Wholesale Lead Capture, The Events Calendar). Acting now significantly reduces the likelihood of a complete intrusion and the resulting loss of data or reputation.

Coverage

Related

More news on the same subject.