Skip to content

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution.

Attackers Actively Exploiting Critical Vulnerability in WooCommerce Wholesale Lead Capture Plugin

On February 20th, 2026, a critical Unauthenticated Arbitrary File Upload vulnerability was publicly disclosed in WooCommerce Wholesale Lead Capture, a premium WordPress plugin with an estimated 6,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. We added this vulnerability to the Wordfence Intelligence vulnerability database on February 25th, 2026. The Wordfence Firewall has already blocked over 100,000 exploit attempts targeting this vulnerability.

Wordfence Premium, Wordfence Care, and Wordfence Response users received a firewall rule to protect against known exploits targeting this vulnerability in WooCommerce Wholesale Lead Capture on February 27, 2026. Sites using the free version of Wordfence received the same protection 30 days later on March 29, 2026.