Security Update Recommendation for the WooCommerce Wholesale Lead Capture Plugin
Overview
It has been confirmed that vulnerability CVE-2026-27540 (a number identifying a security flaw) in Rymera Web Co’s WooCommerce Wholesale Lead Capture plugin has been exploited in actual attacks.
Affected Systems
- WooCommerce Wholesale Lead Capture plugin versions 2.0.3.1 And earlier.
Vulnerability Details
- Insufficient restrictions on the upload of files in dangerous formats in the plugin’s file upload feature resulted in a pre-authentication arbitrary file upload vulnerability.
- The severity of this vulnerability was rated CVSS 9.0. Recommended Actions
- Apply the patch provided through the latest update.
- Update the WooCommerce Wholesale Lead Capture plugin to version 2.0.3.2 Or later.
- Administrators using this plugin should check their systems for signs of compromise.