logo

WordPress Plugin Attacks: Critical RCE Flaws Exposed

ID: af217204-bbd4-50a1-996f-04b33f252da7

STIX ID: report--af217204-bbd4-50a1-996f-04b33f252da7

Feed Name: CyberNexora News

Threat Score
85/100

Date Published: 2026-09-16

Date Updated: 2026-09-16

Author: Debolina Barik

...
...

The report details active exploitation of critical WordPress plugin vulnerabilities—CVE-2026-27540 in WooCommerce Wholesale Lead Capture (unauthenticated arbitrary file upload used to deploy PHP web shells) and two CVSS 9.8 vulnerabilities in The Events Calendar enabling unauthenticated RCE—notes widespread scanning/attempts (100,000+), provides IoCs, affected versions, and remediation guidance for administrators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.