A WooCommerce plugin is being actively exploited right now. Check if your clients run it

  • publication date
    September 21, 2026
  • categories
    News. WordPress

To be clear upfront: this isn’t a WooCommerce core vulnerability. It’s in Wholesale Lead Capture Plugin for WooCommerce, a premium third-party plugin with an estimated 6,000 active installs, and it’s currently being actively exploited (per Wordfence’s disclosure). This is exactly the kind of niche, low-visibility plugin that ongoing plugin and security maintenance is designed to catch before it becomes an incident.

The details

  • CVE-2026-27540, CVSS 9.8 (Critical) — an unauthenticated arbitrary file upload vulnerability
  • Affects all versions up to and including 2.0.3.1; fixed in 2.0.3.2
  • Missing file-type validation on the plugin’s AJAX upload handler lets an unauthenticated attacker upload a PHP backdoor and get remote code execution — no login required
  • Wordfence’s firewall has already blocked over 100,000 exploit attempts targeting this specific flaw

What agencies should do today

  • Check every client site’s plugin list for “Wholesale Lead Capture Plugin for WooCommerce” (or “WooCommerce Wholesale Lead Capture”)
  • If it’s there and below 2.0.3.2, update it immediately — this one is confirmed under active attack, not a theoretical risk
  • Worth a quick site-wide plugin audit generally: a niche, low-visibility plugin like this is exactly the kind of thing that slips through when maintenance is handled ad hoc rather than as a standing service

What this means for Codelibry clients

If you’re on one of our maintenance plans, we’ve already checked your sites against this plugin — if it’s there, it’s updated, and it’s logged in your monthly maintenance report. Nothing for you to do. If you’re not on a plan, this is exactly the failure mode one is meant to prevent: a plugin nobody remembers installing, quietly running until it’s the one under active attack.

Source: Wordfence

Vitalii Omelchenko
Founder at Codelibry and WordPress enthusiast. Helping digital agencies to protect their margins and do better at website delivery. Need help with wordpress builds? Book a call using the Contact page
our Blog

Explore our Latest Insights

company icon
WordPress 7.1.1 fixes 11 security issues. Update client sites now
News
September 21, 2026
company icon
Click2Shell: the WordPress attack chain that turned one admin click into a remote shell
News
September 21, 2026
company icon
White label development for small agencies
WordPress
September 8, 2026
whatsapp icon