Active Exploits Hit WooCommerce Wholesale Lead Capture and WSO2 API Manager Vulnerabilities
Attackers are using a critical flaw in the WooCommerce Wholesale Lead Capture plugin to deploy PHP web shells and are also probing a token-handling bug in WSO2 API Manager that can enable account takeover, with fixes available in both cases.
Two separate vulnerabilities in widely used web tools are under active attack, exposing both online stores and enterprise APIs.
Security researchers report that a critical vulnerability tracked as CVE‑2026‑27540 affects the WooCommerce Wholesale Lead Capture plugin up to and including version 2.0.3.1. Attackers are exploiting the flaw to plant PHP web shells, giving them remote control over affected servers. One security firm says it has blocked more than 100,000 exploit attempts since June, indicating broad and automated scanning for this weakness.
A second issue, CVE‑2026‑5430, targets WSO2 API Manager. The flaw involves forged authentication tokens that can bypass checks and lead to account takeover. Active exploitation attempts have been observed against this bug as well.
In both cases, a successful attack can let intruders run commands, change configurations or access sensitive data behind the scenes of websites and APIs.
Vendors have released fixes for the WSO2 vulnerability, and updated versions of the WooCommerce Wholesale Lead Capture plugin are available. Key signals to watch are whether exploit volumes continue to rise, whether hosting providers enforce updates for vulnerable sites, and whether any major breaches are eventually tied back to these specific flaws.
Sources
- OSINT