type: cve ยท created: 2026-09-16 ยท updated: 2026-09-16 ยท tags: [cve] ยท confidence: medium ยท severity: critical ยท affected_sectors: [global] ยท au_impact: false
NVD description: An unrestricted upload of a file with a dangerous type: an unauthenticated AJAX handler, wwlc_file_upload_handler, validates the upload extension against an allowlist supplied by the caller through the file_settings request parameter, so adding php to that list permits executable PHP uploads.
The vulnerability is tracked as CVE-2026-27540 and affects plugin versions 2.0.3.1 and older; it is an unauthenticated arbitrary file-upload flaw discovered by researcher Teemu Saarentaus and addressed in version 2.0.3.2, released on 20 February.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-27540 |
| CVSS | 9.0 (Critical) |
| Vendor / product | Rymera Web Co Pty Ltd โ WooCommerce Wholesale Lead Capture |
| Reported | 2026-09-16 |