Hackers Exploit WooCommerce Plugin Bug to Take Over WordPress Sites Without Login

Attackers are actively exploiting a critical flaw in a WooCommerce extension to seize control of WordPress sites without a username or password. The issue affects Wholesale Lead Capture and turns a routine file-upload feature into a direct path to server access. The vulnerability, tracked as CVE-2026-27540, has a CVSS severity score of 9.8 and affects […]

This article has been indexed from Cyber Security News

Read the original article: