Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...
Ninja Forms plugin flaw exploited to hack WordPress sites
Bill Toulas
- October 6, 2026
- 05:00 PM

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.
Both vulnerabilities received aΒ high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
The Ninja Forms plugin for WordPress is installed on more than 500,000 sites and allows creating custom forms without writing code.
WPC Product Bundles for WooCommerce allows storing group products into bundles and is active on more than 30,000 WordPress sites.
The campaign was identified on October 4 by researchers at WordPress security platformΒ Patchstack, against users of WPC Product Bundles for WooCommerce. The next day, the same activity was observed against Ninja Forms.
In both attacks, the same JavaScript payload was delivered from βimgcdn1[.]com,β indicating the same threat actor behind the exploitation attempts against the two plugins.
According to the researchers, the attacker tries to plant malicious JavaScript (x.js) in WooCommerce order data or Ninja Forms submissions. When a logged-in administrator loads the content, the script executes using the authenticated WordPress session.
When launched, it retrieves the necessary administrative nonces and uses legitimate WordPress functions to install a malicious plugin masquerading as βWP Smart Thumbnailsβ version 1.2.4 from βMediaPress Labsβ and create an administrator account.
At that stage, the JavaScript payload and the malicious pluginβs PHP scripts establish four access mechanisms to the compromised site:
- A visible administrator account
- An administrator account concealed from the WordPress user list in the dashboard
- A secret login URL that authenticates as the siteβs oldest existing administrator
- An unauthenticated file manager accessible through a direct request to the malicious pluginβs main PHP file
The file manager can't execute commands, but it could still be used to introduce additional payloads on the site.
Even if the WP Smart Thumbnails plugin is removed from the infected website, the hidden account and secret login URL continue to function as persistence mechanisms through separate auxiliary attack plugins featuring backdated timestamps to evade detection.
βThe [hidden] account does not appear in Users β All Users, does not appear in the Administrator filter, and is not counted in the totals above the list,β Patchstack explains, adding that βIt is a fully privileged administrator the site owner cannot see.β
Patchstack says that exploitation is currently limited, but advisesΒ site admins to upgrade to the latest versions of the affected plugins, WPC Product Bundles for WooCommerce version 8.6.7 or later and Ninja Forms 3.15.4 or later.
Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection. Administrators are strongly recommended to check for signs of compromise.
Build your security blueprint for AI-powered attacks
Join Mikko HyppΓΆnen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seatOriginally published by BleepingComputer. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.