Active Exploitation Hits WooCommerce Wholesale Lead Capture CVE-2026-27540
Unauthenticated file upload CVE-2026-27540 in WooCommerce Wholesale Lead Capture is under active exploitation. Update to 2.0.3.2 and inspect uploads.
Wednesday, October 7, 2026
News For Internet Marketers
Unauthenticated file upload CVE-2026-27540 in WooCommerce Wholesale Lead Capture is under active exploitation. Update to 2.0.3.2 and inspect uploads.
Square directed sellers to remove CBD, hemp, and hemp-derived items by October 15, 2026. Processor deadlines can arrive before federal hemp dates shift.