S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Aug 14, 2026

CVE-2026-27542 Scanner

CVE-2026-27542 Scanner - Privilege Escalation vulnerability in WooCommerce Wholesale Lead Capture

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-27542
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

Incorrect Privilege Assignment vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture woocommerce-wholesale-lead-capture allows Privilege Escalation.This issue affects Woocommerce Wholesale Lead Capture: from n/a through <= 2.0.3.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Woocommerce Wholesale Lead Captureby Rymera Web Co Pty Ltd.
0
Updated Aug 19, 2026View on NVD →
Detail

WooCommerce Wholesale Lead Capture is a popular plugin for the WordPress platform, designed to enhance e-commerce capabilities. It is primarily used by businesses and online vendors to manage wholesale customer registration and streamline the lead capture process. The plugin is developed by Rymera Web Co Pty Ltd and is integrated within WooCommerce, a widely-used e-commerce framework for WordPress. Designed for simplicity and efficiency, it automates the wholesale customer management for websites, offering features like registration forms, custom fields, and user roles. IT professionals and website administrators utilize this plugin to enhance the B2B e-commerce experience while managing customer information securely. This tool is essential for businesses that want to differentiate between retail and wholesale customers without complex coding implementations.

The vulnerability in WooCommerce Wholesale Lead Capture involves a broken access control, which can lead to privilege escalation. This security flaw arises due to improper privilege assignments, allowing unauthenticated users to gain higher-level access within the system. The issue allows attackers to exploit the vulnerability without needing special conditions, posing a significant risk to the affected systems. This can potentially allow attackers to perform actions that are restricted to privileged accounts. It represents a serious threat to websites using this plugin, as unauthorized access can lead to data leaks and potential misuse of administrative functions. The critical nature of this vulnerability necessitates immediate attention and remediation to protect sensitive business operations.

Technically, the vulnerability stems from the misconfiguration within the '/wp-admin/admin-ajax.php' endpoint. It allows unauthenticated users to execute the 'wwlc_create_user' action without proper authorization checks. Furthermore, a GET request to the '/wp-content/plugins/woocommerce-wholesale-lead-capture/readme.txt' file can verify the plugin's presence and its exploited version. The vulnerable parameter 'action=wwlc_create_user' is misused to escalate privileges and create new users without permission. The exploitation can occur when the system fails to return error codes effectively or when it inadvertently approves unauthorized HTTP actions. This presents a significant threat if left unpatched within a business's e-commerce infrastructure. The implications call for immediate updates beyond version 2.0.3.1 to mitigate these risks.

Once exploited, the vulnerability allows attackers to assume unauthorized privileges within the system. This escalation can grant them access to critical application features or sensitive customer data. Such control enables attackers to manipulate, steal, or delete data, and even disrupt services by altering system configurations. It poses a risk of unauthorized transactions or database modifications, endangering the company's credibility and customer trust. Cybercriminals could use the escalated privileges to launch further attacks within the network infrastructure, potentially leading to a full-scale breach. Therefore, addressing this vulnerability is crucial to maintaining the security and integrity of the business's digital operations.

REFERENCES

Solution Advice
  • Update WooCommerce Wholesale Lead Capture to the latest version beyond 2.0.3.1 to ensure the vulnerability is patched.
  • Regularly review access controls and authentication processes to ensure they meet current security standards.
  • Implement logging and monitoring to detect any unauthorized access attempts promptly.
  • Conduct periodic penetration testing to identify and remediate potential vulnerabilities efficiently.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.