BlackTree Security · Infrastructure · Automation · AI

This Shop Plug-in Let Attackers Decide Which Files Were Safe to Upload

An upload filter is supposed to make a decision the visitor cannot control. In vulnerable versions of Wholesale Lead Capture for WooCommerce, the person submitting a file could supply the list of file types the handler considered acceptable. Attackers could effectively write their own permission slip.

Wordfence’s 14 September threat report says its firewall has blocked more than 100,000 attempts against CVE-2026-27540, a critical unauthenticated arbitrary-file-upload flaw. Its affected-version table identifies 2.0.3.1 and earlier, with 2.0.3.2 the first fixed release. This affects a specific third-party premium plug-in, not every WooCommerce store or a newly announced flaw in WooCommerce itself.

The check trusted the attacker’s answer

The public upload handler read permitted file types from the request rather than authoritative server-side settings. Wordfence describes attackers using that control to submit PHP web shells, which can execute code and provide a route for further malicious files. The researchers report exploitation over several months. The blocked-request count is not a count of infected shops, affected customers or successful compromises.

The vendor’s current changelog lists releases beyond 2.0.3.2, including 2.0.6, and additional hardening. Administrators should obtain a current maintained release through the legitimate update channel and verify that it includes the relevant fix. “At least the first fixed version” is not the same as a recommendation to stop updating at an old minimum.

Finding a newer version does not answer the historical question

Wordfence recommends reviewing unexpected PHP files, relevant upload-handler requests and unfamiliar administrator accounts. A patch removes the vulnerable behaviour; it does not establish that a previously uploaded web shell has disappeared. The response therefore needs to distinguish current version compliance from evidence of what happened while the site was vulnerable.

BlackTree’s recommendation is to start with the actual plug-in inventory across live, staging and less-used sites. E-commerce operators often have several owners involved: a merchant, an agency, a hosting company and someone maintaining premium licences. An update can remain undone when each assumes another party owns it. Put a named person against the installation and a verified build against the remediation ticket.

Four checks before the ticket closes

  • Identify the exact component. Check whether Wholesale Lead Capture is installed and which version is actually running. Do not substitute the version of WooCommerce or another Wholesale Suite component.
  • Apply and verify the supported fix. Use the legitimate vendor channel and a maintained fixed release. Validate the registration and upload workflow after the update rather than assuming a green notification means it works correctly.
  • Investigate the exposed period. Review relevant files, application and web logs with qualified responders. Preserve suspicious material safely; do not execute it to see what it does. Treat absence of a known filename as an incomplete check, not proof of cleanliness.
  • Separate recovery from patch installation. If compromise is established, scope attacker access and persistence, choose a trustworthy recovery point and assess credentials accessible to the site. Record the evidence supporting return to service.

For engineering teams, the design lesson reaches beyond WordPress. A client can describe the file it wants to send, but it must not define the server’s security policy for accepting it. Enforce the decision using trusted server-side rules, and test the deployed handler’s actual behaviour rather than relying on what the form tells users is permitted.

This is related to the trust-boundary problem in BlackTree’s reporting on a separate WordPress backup-component flaw, not evidence of a shared campaign. A useful feature becomes an attack route when the system grants untrusted input more authority than it should have.

The news is not that the flaw was discovered today. It is that an old, fixable mistake is still attracting attacks. The question for a shop owner is whether the installation was fixed, and whether someone checked what arrived before that happened.

Sources

One comment

  1. pasted

    Thank you for this clear write-up; the point that a client may describe the file it wants to send but must never define the server’s upload policy is a valuable design lesson, and the reminder that installing the patch does not prove an earlier web shell is gone makes the incident response advice very practical.

Leave a Reply

Your email address will not be published. Required fields are marked *