build1 publisher
Attackers are telling a WooCommerce plugin that PHP is an allowed upload extension
CVE-2026-27540 lets an unauthenticated POST save a PHP file, and 2.0.3.2 closes that write. Whether a file that already landed can run is a separate question, decided by how the server treats the upload directory.
Publishers:dev.to
Reality
- Evidence60
- Adoption38
- Hype gap+10
- Incentives45
- Confidence55