Cybersecurity

Vulnerabilities in Ninja Forms and WPC Product Bundles Plugins Exploited to Compromise WordPress Sites

Attackers are exploiting stored XSS vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce plugins to plant backdoors and create hidden administrator accounts. Users are advised to update to Ninja Forms version 3.15.4 or later and WPC Product Bundles version 8.6.7 or later, while scanning sites that may have already been compromised.

2026-10-06
3 min read
0 views
certi.news Editorial Team
Vulnerabilities in Ninja Forms and WPC Product Bundles Plugins Exploited to Compromise WordPress Sites

Researchers have observed active exploitation of two stored cross-site scripting (XSS) vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce plugins, enabling attackers to plant backdoors and create hidden administrative accounts on WordPress sites. Although exploitation requires an authenticated session, its impact is significant when a site administrator loads the infected data.

Scope of the Vulnerabilities and Exploitation

The WPC Product Bundles for WooCommerce vulnerability is tracked as CVE-2026-93836 and affects version 8.6.6 and earlier, while the Ninja Forms vulnerability is tracked as CVE-2026-94504 and affects version 3.15.3 and earlier. Ninja Forms, which enables the creation of custom forms without writing code, is used on more than 500,000 sites, while the WPC Product Bundles for WooCommerce plugin is active on more than 30,000 sites.

WordPress security platform Patchstack identified the campaign on October 4, when it targeted users of WPC Product Bundles for WooCommerce, then observed the same activity against Ninja Forms the following day. The same payload was delivered from the domain imgcdn1[.]com in both attacks, indicating that a single threat actor is behind the exploitation.

How Is Covert Access Planted?

The attacker attempts to insert malicious JavaScript code named x.js into WooCommerce order data or Ninja Forms submissions. When a logged-in administrator opens this data, the code runs within the authenticated WordPress session, then extracts the necessary administrative tokens and uses legitimate WordPress functions to install a malicious plugin masquerading as WP Smart Thumbnails, version 1.2.4, and attributed to an entity named MediaPress Labs.

The payload then creates an administrative account and provides several ways to regain access, including a visible administrator account, another account hidden from the user list, and a secret login link that impersonates the session of the site's oldest administrator, in addition to a file manager that can be accessed without authentication through a direct request to the plugin's main file. Although the file manager does not execute system commands, it may allow additional payloads to be inserted.

What Does This Mean for Site Administrators?

Deleting the WP Smart Thumbnails plugin is not enough to remove the infection. The hidden accounts and secret login link may remain active through auxiliary malicious plugins bearing old dates to conceal them from scans. Patchstack also explained that the hidden account does not appear in the list of all users or in the administrator filter, and is not included in the total counts, while retaining full administrator privileges.

Patchstack recommends updating to WPC Product Bundles for WooCommerce 8.6.7 or later and Ninja Forms 3.15.4 or later. The update prevents subsequent exploitation, but it does not clean an existing infection; therefore, users should inspect users, plugins, files, and login logs for indicators of compromise, bearing in mind that the absence of the malicious account from the dashboard does not necessarily mean it has been removed.

News source
BleepingComputer
Open original source ↗
c
Author

certi.news Editorial Team

In the same category

You may also like

View all news