Summary
A critical vulnerability (CVE-2026-27540) in the WooCommerce Wholesale Lead Capture Plugin for WordPress is being actively exploited, allowing attackers to upload PHP backdoors and potentially take over websites. Users are urged to update to version 2.0.3.2 or newer and check for malicious files.