Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-09-16 ยท updated: 2026-09-16 ยท tags: [cve] ยท confidence: medium ยท severity: critical ยท affected_sectors: [global] ยท au_impact: false

NVD description: An unrestricted upload of a file with a dangerous type: an unauthenticated AJAX handler, wwlc_file_upload_handler, validates the upload extension against an allowlist supplied by the caller through the file_settings request parameter, so adding php to that list permits executable PHP uploads.

The vulnerability is tracked as CVE-2026-27540 and affects plugin versions 2.0.3.1 and older; it is an unauthenticated arbitrary file-upload flaw discovered by researcher Teemu Saarentaus and addressed in version 2.0.3.2, released on 20 February.

Attribute Detail
CVE CVE-2026-27540
CVSS 9.0 (Critical)
Vendor / product Rymera Web Co Pty Ltd โ€” WooCommerce Wholesale Lead Capture
Reported 2026-09-16