Critical Unauthenticated File Upload Flaw in WooCommerce Wholesale Lead Capture Enables Active PHP Web Shell Attacks
Attackers are actively exploiting a critical vulnerability in the premium WooCommerce Wholesale Lead Capture plugin to compromise WordPress sites and gain full control of the underlying server.
The flaw, identified as CVE-2026-27540 and rated CVSS 9.8, permits unauthenticated file uploads. Attackers can plant a PHP web shell and execute arbitrary commands remotely. The issue impacts all installations running version 2.0.3.1 and earlier.
The technical vector centers on the publicly accessible AJAX endpoint wwlc_file_upload_handler. This handler validates file extensions against an allowlist that an attacker can override by manipulating the file_settings parameter, enabling PHP files to be accepted. Once uploaded, the shell can be executed directly from the browser to deploy additional payloads, steal credentials, or establish persistence.
Telemetry shows more than 100,000 exploitation attempts blocked since June 2026, with notable spikes between 4–17 June, on 1 July, and on 30 August. Multiple repeat IP addresses have generated tens of thousands of requests, consistent with automated scanning campaigns targeting vulnerable sites across the internet.
The developer published WooCommerce Wholesale Lead Capture 2.0.3.2 on 20 February 2026. Sites that cannot update immediately should disable or remove the plugin. Administrators must also scan wp-content/uploads for unexpected or recently created .php files and review logs for requests to /wp-admin/admin-ajax.php with the action wwlc_file_upload_handler.
Additional defensive measures include deploying WAF rules to block malicious uploads via admin-ajax.php and monitoring for repeated failed or successful requests from the same sources. In cases of confirmed intrusion, simply deleting a single file is insufficient; unknown administrator accounts should be removed, credentials rotated, and the site restored from a verified clean backup after hardening.
Related articles
Microsoft Fixes CVE-2026-96940 in Exchange Server Allowing Authenticated Mailbox Access
Microsoft has patched CVE-2026-96940, a CVSS 8.8 vulnerability in Exchange Server that lets any authenticated user read other users' mailboxes without administrative rights. The flaw exposes full message content and attachments including contracts, spreadsheets, and sensitive documents. Affected on-premises versions include Exchange Server Subscription Edition RTM, Exchange 2016 CU23, Exchange 2019 CU15, and Exchange 2019 CU14. Exchange Online users are protected because the fix was applied server-side. Microsoft rates exploitation as likely but reports no confirmed attacks in the wild at disclosure time. The issue turns a single low-privilege credential into broad access to executive, legal, and financial correspondence.
New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction
Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.
Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score
Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.
Fortinet Releases FortiMail Updates to Patch Zero-Day CVE-2026-104286
Fortinet has begun distributing updates for its FortiMail email security product to address the zero-day vulnerability CVE-2026-104286. The flaw allows unauthenticated attackers to write arbitrary files to the system by sending specially crafted HTTP requests. The company first published a security advisory on October 1, 2026, confirming active exploitation and providing Indicators of Compromise while preparing fixes. On October 5, 2026, Fortinet updated the advisory and released patched versions including FortiMail 8.0.2, 7.6.7, and 7.4.9. Organizations still running the 7.2 branch are advised to migrate to the 7.4 branch or later to obtain protection. The advisory reference is FG-IR-26-175.