CVE-2026-27540

WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Using Malicious Files.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.


We have discovered 117 live websites that are affected by CVE-2026-27540.

Run a Free Instant Scan





Details

  • Published - Mar 19, 2026
  • Updated - Apr 29, 2026

Credits

  • Teemu Saarentaus | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-27540
United States61 websites



GB10 websites
Netherlands7 websites
Australia4 websites
Germany4 websites
Austria3 websites
Denmark3 websites
Canada2 websites
Switzerland2 websites
Finland2 websites

Website Distribution by TLD

Number of websites using CVE-2026-27540
.com65 websites
.co.uk7 websites
.nl5 websites
.se4 websites
.com.au4 websites
.de4 websites
.dk4 websites
.at2 websites
.ch2 websites
.fi2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-27540

Top websites that are affected by CVE-2026-27540. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States***,***
**********.at Austria***,***
*********.se United States***,***
**********.com United States***,***
*******.com United States***,***
*********.com United States***,***
*******.***************.nl Netherlands***,***
****************.com United States***,***
**********.com United States***,***
***********.com United States***,***
See full domain list