The record
Written from the 1 report below. Nothing here is unsourced.
- Attackers are exploiting a critical flaw in the WooCommerce Wholesale Lead Capture WordPress plugin to upload PHP web shells and achieve remote code execution.
- The vulnerability, tracked as CVE-2026-27540 with a CVSS score of 9.8, affects all plugin versions up to and including 2.0.3.1 and stems from missing file type validation in the wwlc_file_upload_handler AJAX action.
- Wordfence has blocked over 100,000 exploit attempts targeting the flaw since June 2026, and the plugin has more than 6,000 active installs.
- Wordfence also detailed two critical flaws in The Events Calendar plugin, installed on over 600,000 websites, that could allow unauthenticated remote code execution and complete site takeover.
- The Events Calendar developer StellarWP has released fixes in versions 6.17.3.1 and 6.17.4.1, and site owners are urged to update and check for unexpected .php files in the uploads directory.
What to watch next
- Check for unexpected or recently created .php files, especially in the uploads directory.
- Review logs for suspicious requests to /wp-admin/admin-ajax.php with the action parameter set to wwlc_file_upload_handler from the listed IP addresses.
- Verify WordPress sites are updated to The Events Calendar versions 6.17.3.1 or 6.17.4.1 and a patched version of WooCommerce Wholesale Lead Capture.
Coverage1
1 report
English national1
All filed from India
Named India · StellarWP · The Events Calendar · WooCommerce Wholesale Lead Capture · Wordfence
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
