Security News Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells TheHackerNews Daniel Bender 16 Sep 2026 Share Attackers are exploiting CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells and gain remote code execution.