Executive Summary
In June 2026, a surge in exploitation attempts was observed targeting WordPress environments, specifically focusing on the WooCommerce Wholesale Lead Capture plugin. The primary vulnerability, CVE-2026-27540, allows unauthenticated attackers to bypass file type validation and upload malicious PHP scripts. Over 100,000 exploit attempts have been blocked, indicating a highly active and automated campaign.
Simultaneously, critical vulnerabilities (CVE-2026-78159 and CVE-2026-78006) were identified in 'The Events Calendar' plugin, affecting over 600,000 installs. These flaws enable remote code execution (RCE) via PHP Object Injection or arbitrary-callable primitives, which can lead to administrator password resets and total site compromise. These attacks are particularly dangerous as they can be triggered through pending-comment previews without moderator approval.
The impact of these vulnerabilities includes complete server compromise, sensitive data exfiltration, and the use of infected hosts for further malware distribution. Organizations using these plugins should prioritize immediate patching and perform forensic reviews of their web directories for unauthorized PHP files.
