WordPress Plugin Attacks: Critical RCE Flaws Exposed
ID: af217204-bbd4-50a1-996f-04b33f252da7
STIX ID: report--af217204-bbd4-50a1-996f-04b33f252da7
Feed Name: CyberNexora News
Threat Score
The report details active exploitation of critical WordPress plugin vulnerabilities—CVE-2026-27540 in WooCommerce Wholesale Lead Capture (unauthenticated arbitrary file upload used to deploy PHP web shells) and two CVSS 9.8 vulnerabilities in The Events Calendar enabling unauthenticated RCE—notes widespread scanning/attempts (100,000+), provides IoCs, affected versions, and remediation guidance for administrators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
