XSS Vulnerabilities in Ninja Forms and WPC Product Bundles Exploited to Attack WordPress Websites
555/69 Thursday, October 8, 2026 Researchers from Patchstack have disclosed active exploitation of Stored Cross-Site Scripting (XSS) vulnerabilities in two WordPress plugins: Ninja Forms, tracked as CVE-2026-94504 and affecting version 3.15.3 and earlier, and WPC Product Bundles for WooCommerce, tracked as CVE-2026-93836 and affecting version 8.6.6 and earlier. In both cases, attackers used JavaScript payloads […]
