Security Update Recommendation for the WooCommerce Wholesale Lead Capture Plugin

Security Update Recommendation for the WooCommerce Wholesale Lead Capture Plugin

Overview

It has been confirmed that vulnerability CVE-2026-27540 (a number identifying a security flaw) in Rymera Web Co’s WooCommerce Wholesale Lead Capture plugin has been exploited in actual attacks.

Affected Systems

  • WooCommerce Wholesale Lead Capture plugin versions 2.0.3.1 And earlier.

Vulnerability Details

  • Insufficient restrictions on the upload of files in dangerous formats in the plugin’s file upload feature resulted in a pre-authentication arbitrary file upload vulnerability.
  • The severity of this vulnerability was rated CVSS 9.0. Recommended Actions
  • Apply the patch provided through the latest update.
  • Update the WooCommerce Wholesale Lead Capture plugin to version 2.0.3.2 Or later.
  • Administrators using this plugin should check their systems for signs of compromise.