Attackers are currently exploiting a security flaw in the Wholesale Lead Capture Plugin for WooCommerce, a premium plugin used by more than 20,000 websites. The vulnerability, identified as CVE-2026-27540, allows unauthorized users to upload arbitrary files to a website, potentially enabling them to deploy PHP webshells—small pieces of malicious code that can be used to take control of a website. This flaw was addressed in version 2.0.3.2 of the plugin, which was released on February 20, 2026. However, the issue remains a target for attackers, as reported by security firm Defiant. According to Defiant, its Wordfence web application firewall detected and blocked over 100,000 attempts to exploit this vulnerability between June 4 and August 30, 2026. These attacks primarily involved the uploading of reconnaissance webshells, which attackers can use to gather information about the website's structure and identify potential weaknesses. This initial phase often precedes more severe attacks, such as data theft or full website compromise. The Wholesale Lead Capture Plugin is widely used by online retailers who rely on WooCommerce, a popular e-commerce platform for WordPress. The plugin helps businesses capture leads from wholesale customers, making it a valuable tool for many site owners. However, the ongoing exploitation of this vulnerability highlights the importance of timely software updates to protect against emerging threats. Website administrators who use the Wholesale Lead Capture Plugin are strongly advised to update to the latest version of the plugin to close this security gap. Additionally, they should review their server's upload directories for any unexpected or recently created PHP files, which could indicate a breach. Keeping software up to date and monitoring system logs are essential steps in maintaining website security.