Vulnerability threat dossier

CVE-2026-27540

Rymera Web Co Pty Ltd.Woocommerce Wholesale Lead Capture

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

VTP deterministic threat21.0of 100 · CVSS excluded

VTP analyst assessment

WooCommerce Wholesale Lead Capture exploitation reported

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence70%
Public exploitation · VTP factREPORTED

Assessment

BleepingComputer and The Hacker News report exploitation of CVE-2026-27540 in WooCommerce Wholesale Lead Capture. The vulnerable plugin accepts dangerous file uploads through version 2.0.3.1, which reporting says attackers use to upload PHP backdoors.

Why it matters

  • A vulnerable WordPress site can give an unauthenticated attacker a route to place server-side files.
  • A PHP backdoor could enable code execution through the web server.

Evidence

2 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The two reports may rely on the same underlying reporting.

The reports do not establish exploitation of any specific customer site.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use WooCommerce Wholesale Lead Capture through 2.0.3.1, apply vendor remediation immediately.

AI baseline history (3)
  1. BASELINE ASSESSED
    WooCommerce Wholesale Lead Capture exploitation reportedgpt-5.6-terra · low
  2. BASELINE ASSESSED
    WooCommerce Wholesale Lead Capture upload flaw is reportedly exploitedgpt-5.6-terra · low
  3. BASELINE ASSESSED
    Reported WordPress plugin exploitation requires CVE mappinggpt-5.6-terra · low
Technical severityCRITICALCVSS 9.0 · technical context
Public exploitationREPORTEDGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS0.0283th percentile · prediction
Evidence confidence60%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    EPSS is 0.02; this is predictive context, not exploitation evidence.

  2. 02

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

No material changes are recorded for this subject.

03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:fc475f0a67bcb883820d2d8331ded679fbd9ec637447bf834f16c6889923bde0ACTIVE
Evidence
04

Event history

Threat timeline

  1. 14:4515 Sept
    EXPLOITATION REPORTED

    Exploitation Reported

    BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

05

Original publications

Source record

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

CVE-2026-27540CVE-2026-78006CVE-2026-78159
Separate evidence group
Original

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

CVE-2026-27540
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score21.0vtp-threat-v1-public
Public exploitation12 / 30
EPSS prediction0.46 / 20
Exploit availability2.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-434
CPE records
0
Deterministic history records
9
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.