Two WordPress plugins, two compromises, one week

· · Security

If your business runs on WordPress, or you built a client's site on it, you probably could not list every plugin installed from memory. Most sites carry between 15 and 40. Somebody added each one to solve a problem: take payments, capture leads, tweak the admin menu, speed up page loads. Then everyone moved on, and the plugin kept running with the same access to your site it had on day one.

Two unrelated incidents this week show what that adds up to. Different causes, same lesson: the thing attacking a WordPress site is rarely WordPress itself. It is one of the plugins nobody has looked at since it was installed.

An unpatched flaw being actively exploited

WooCommerce Wholesale Lead Capture is a paid plugin, installed on over 6,000 sites, that lets WooCommerce stores offer trade pricing to registered buyers. It carries a critical flaw, tracked as CVE-2026-27540 and rated 9.8 out of 10, that lets an attacker upload files to the server with no login at all. The plugin was supposed to check that an uploaded file was actually an image or document. It did not.

According to Wordfence, the WordPress security firm that tracks attacks like this, it has blocked over 100,000 exploit attempts against this flaw since June. Attackers drop a PHP web shell, a small script that gives them a remote command line on your server, plus a form for uploading further malicious files. From there they can read your database or add themselves an administrator account.

This is the ordinary version of a plugin compromise. A flaw sat in the code, a fix eventually shipped, and every site running an older version stayed exposed in the gap between the two, a gap still open for many sites months later.

A trusted update that was not trustworthy

Admin Menu Editor Pro is a different plugin entirely, unrelated to WooCommerce, used to customise the WordPress admin dashboard menu. Its maintainer's own website was compromised, and a malicious version went out through the normal update mechanism, the same one that delivers a legitimate fix. Anyone who updated as usual received it.

The affected update created a hidden administrator account and installed a web shell. By the maintainer's own account, at least 230 customers across roughly 1,500 sites installed the compromised release before it was pulled, and a second, supposedly clean version was tampered with afterwards too. Updating promptly, normally exactly the right instinct, is what delivered the backdoor here.

Why both matter even though neither is WordPress's fault

Neither plugin is obscure or badly reviewed. Both solve a real problem people pay for. That is the point: your site's actual attack surface is the sum of every plugin it runs, not WordPress core, and most of those are things a site owner installed once and never thought about again.

Checking whether WordPress itself is current, the advice most people already follow, would not have caught either of these. One needed a specific plugin patched. The other needed nobody to have installed an update during a seven-hour window. The only defence that covers both is knowing exactly what you are running, and checking it afterwards rather than assuming an update always makes things safer.

What to check this week

  • List every plugin on your site. Check the actual plugins screen, or ask whoever manages the site to send you the list.
  • If you run WooCommerce Wholesale Lead Capture, confirm you are on the current version and check your uploads directory for any .php file you did not put there, particularly one named shell.php.
  • If you run Admin Menu Editor Pro, check your admin user list for any account you do not recognise, and look for unfamiliar files in your plugins or content directories.
  • For every plugin, note who maintains it and when it last updated. A plugin with no update in over a year is not automatically dangerous, but nobody is watching it either.
  • Turn on automatic updates for security releases where your host supports it, and keep a record of what changed, so an unexpected update is something you would notice.

How Steelwise can help

Working out exactly what a website runs, who maintains each part of it, and whether anything looks out of place is exactly the kind of security review we do for small businesses without an in-house technical team. Get in touch.

Further reading

← All filings