security3 publishers
Wordfence blocked 100,000 exploit attempts against a WooCommerce plugin with 6,000 installs
CVE-2026-27540 lets an unauthenticated request add php to the plugin's own upload allowlist and drop a webshell. The fix shipped on February 20, and the first exploitation spike came 104 days later, on June 4.
Reality
- Evidence68
- Adoption55
- Hype gap+15
- Incentives74
- Confidence62