A critical vulnerability in WooCommerce Wholesale Lead Capture, a premium plugin installed on an estimated 6,000 WordPress sites, is under active attack. Wordfence says its firewall has blocked over 100,000 exploit attempts targeting it.
What happened
The flaw, tracked as CVE-2026-27540, lets an unauthenticated attacker upload arbitrary files, including PHP backdoors that hand them remote code execution on your server. Wordfence rates it 9.8 out of 10, its highest severity tier. It affects WooCommerce Wholesale Lead Capture version 2.0.3.1 and earlier.
Wordfence added the vulnerability to its database on February 25, 2026, and shipped a firewall rule for Wordfence Premium, Care, and Response users on February 27. Free Wordfence users received the same protection 30 days later, on March 29. The plugin’s developer patched the flaw in version 2.0.3.2.
What to do
- Update WooCommerce Wholesale Lead Capture to version 2.0.3.2 or later from your WordPress dashboard now.
- If you’re on Wordfence Premium, Care, or Response, you’ve had a firewall rule blocking known exploit attempts since February 27. Free Wordfence users have had it since March 29.
- If your site has been running an outdated version, check your server for unfamiliar PHP files, especially in upload directories, since attackers have had months to exploit this bug.
End of article