WordPress Plugins Exploited for Remote Code Execution
Score: 7/10

WordPress Plugins Exploited for Remote Code Execution

Threat actors are exploiting critical vulnerabilities in WooCommerce Wholesale Lead Capture and The Events Calendar plugins to deploy PHP web shells and achieve full site takeover.

Executive Summary

In June 2026, a surge in exploitation attempts was observed targeting WordPress environments, specifically focusing on the WooCommerce Wholesale Lead Capture plugin. The primary vulnerability, CVE-2026-27540, allows unauthenticated attackers to bypass file type validation and upload malicious PHP scripts. Over 100,000 exploit attempts have been blocked, indicating a highly active and automated campaign.

Simultaneously, critical vulnerabilities (CVE-2026-78159 and CVE-2026-78006) were identified in 'The Events Calendar' plugin, affecting over 600,000 installs. These flaws enable remote code execution (RCE) via PHP Object Injection or arbitrary-callable primitives, which can lead to administrator password resets and total site compromise. These attacks are particularly dangerous as they can be triggered through pending-comment previews without moderator approval.

The impact of these vulnerabilities includes complete server compromise, sensitive data exfiltration, and the use of infected hosts for further malware distribution. Organizations using these plugins should prioritize immediate patching and perform forensic reviews of their web directories for unauthorized PHP files.

Key Details

Threat Name

CVE-2026-27540

Affects

WooCommerce Wholesale Lead Capture plugin up to 2.0.3.1, The Events Calendar <= 6.17.3, The Events Calendar <= 6.17.4

Adversary

—

MITRE Techniques

Malware/Tools

PHP Web Shells

Report Score

7out of 10
Quality Score
Good
IOC Quality8
TTP Details7
Detection Guidance6
Enterprise Relevance6
Clarity & Structure9
Technical Depth7

Sources