
WooCommerce Plugin Bug Lets Remote Attackers Create Admin Accounts and Take Over Sites
A critical security flaw in the WooCommerce Wholesale Lead Capture plugin is being actively exploited, allowing remote attackers to upload malicious files and potentially take full control of vulnerable WordPress sites. The vulnerability, tracked as CVE-2026-27540, affects WooCommerce Wholesale Lead Capture versions 2.0.3.1 and earlier. The premium plugin, used by an estimated 6,000 websites, helps […]
The post WooCommerce Plugin Bug Lets Remote Attackers Create Admin Accounts and Take Over Sites appeared first on Cyber Security News.