CVE-2026-27540
Received Received - Intake
Unrestricted File Upload Vulnerability in Woocommerce Wholesale Lead Capture

Publication date: 2026-03-19

Last updated on: 2026-04-29

Assigner: Patchstack

Description
Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-19
Last Modified
2026-04-29
Generated
2026-06-16
AI Q&A
2026-03-19
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
rymera_web_co woocommerce_wholesale_lead_capture From 2.0.0 (inc) to 2.0.3.1 (inc)
rymera_web_co woocommerce_wholesale_lead_capture 2.0.3.2
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-27540 is a high-priority arbitrary file upload vulnerability in the WordPress WooCommerce Wholesale Lead Capture Plugin versions up to 2.0.3.1.

This flaw allows unauthenticated attackers to upload arbitrary files, including malicious backdoors, which can then be executed to gain unauthorized access and control over affected websites.

The vulnerability is classified under the OWASP Top 10 category A3: Injection and requires no privileges to exploit, making it particularly dangerous.

Impact Analysis

This vulnerability can have severe impacts as it allows attackers to upload and execute malicious files on your website without any authentication.

Successful exploitation can lead to unauthorized access and control over your website, potentially resulting in data breaches, defacement, or further attacks on your infrastructure.

Because the vulnerability requires no privileges to exploit, it poses a high risk to all users of the affected plugin versions.

Compliance Impact

I don't know

Detection Guidance

[{'type': 'paragraph', 'content': 'This vulnerability allows unauthenticated attackers to upload arbitrary files, including malicious backdoors, to affected websites. Detection can involve monitoring for unusual file uploads or the presence of unexpected files in the WooCommerce Wholesale Lead Capture plugin directories.'}, {'type': 'paragraph', 'content': 'While specific commands are not provided in the resources, general detection methods include scanning the web server directories for recently added or modified files that are not expected, especially executable scripts or files with dangerous extensions.'}, {'type': 'list_item', 'content': "Use commands like 'find /path/to/wordpress/wp-content/plugins/woocommerce-wholesale-lead-capture/ -type f -mtime -7' to find files modified or added in the last 7 days."}, {'type': 'list_item', 'content': 'Check web server logs for suspicious POST requests to upload endpoints related to the plugin.'}, {'type': 'list_item', 'content': "Use malware scanning tools such as 'clamscan' or 'maldet' to detect malicious files on the server."}] [1]

Mitigation Strategies

The most immediate and effective mitigation step is to update the WooCommerce Wholesale Lead Capture plugin to version 2.0.3.2 or later, where the vulnerability is patched.

Until the update can be applied, users can implement the mitigation rule provided by Patchstack to block attacks targeting this vulnerability.

Additionally, enabling automatic mitigation and auto-update features offered by Patchstack can enhance protection against exploitation.

It is also advisable to review and restrict file upload permissions and monitor for suspicious activity on the affected systems.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-27540. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart