Follow the latest coverage, related explainers and connected technology stories.
Attackers are exploiting stored XSS vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce plugins to plant backdoors and create hidden administrator accounts. Users are advised to update to Ninja Forms version 3.15.4 or later and WPC Product Bundles version 8.6.7 or later, while scanning sites that may have already been compromised.