On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. We added this vulnerability to the Wordfence Intelligence vulnerability database on February 25th, 2026.
Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin
About this summary. This is a short, independently written summary of an article first published by Wordfence. Cyber Security News did not report or verify the underlying story. Read the original: https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-woocommerce-wholesale-lead-capture-plugin/

Source attribution: headline and facts are from Wordfence (wordfence.com). Summary method: excerpt of the source description. See our source attribution policy and corrections policy.

