XSS Vulnerabilities in Ninja Forms and WPC Product Bundles Exploited to Attack WordPress Websites

Views: 46 views

555/69 Thursday, October 8, 2026

Researchers from Patchstack have disclosed active exploitation of Stored Cross-Site Scripting (XSS) vulnerabilities in two WordPress plugins: Ninja Forms, tracked as CVE-2026-94504 and affecting version 3.15.3 and earlier, and WPC Product Bundles for WooCommerce, tracked as CVE-2026-93836 and affecting version 8.6.6 and earlier. In both cases, attackers used JavaScript payloads from the same infrastructure to deploy backdoors and create administrator accounts on compromised websites.

Attackers can submit malicious JavaScript through WooCommerce order data or information submitted through Ninja Forms. When an authenticated administrator views the affected data, the script executes within the administrator’s session and abuses WordPress functionality to install a malicious plugin disguised as “WP Smart Thumbnails.” The attackers then establish multiple methods of accessing the website, including a visible administrator account, a hidden administrator account that does not appear in the user list, a secret login link, and a file manager accessible without authentication. Some components are installed as Must-Use plugins, allowing them to remain on the website even if the primary malicious plugin is removed.

Website administrators should update Ninja Forms to version 3.15.4 or later and WPC Product Bundles for WooCommerce to version 8.6.7 or later. They should also check for the wp-smart-thumbnails plugin, unknown administrator accounts, and suspicious files in the mu-plugins directory. Updating the affected plugins can prevent further exploitation of the vulnerabilities, but it will not remove backdoors or persistence mechanisms that may already have been installed. Patchstack stated that the volume of attacks observed at the time of the report remained limited, but confirmed that both vulnerabilities have been exploited in real-world attacks.

Source: https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/