Back to Feed
VulnerabilitiesOct 6, 2026

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers exploit XSS flaws in Ninja Forms and WPC Product Bundles to install backdoors on WordPress sites.

Summary

Hackers are actively exploiting stored XSS vulnerabilities in the popular Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins. These attacks, tracked as CVE-2026-93836 and CVE-2026-94504 respectively, allow threat actors to install backdoors and create hidden administrator accounts on compromised sites. The exploitation involves planting malicious JavaScript that, when executed by an administrator, installs a plugin named 'WP Smart Thumbnails' and establishes multiple persistence mechanisms.

Full text

Ninja Forms plugin flaw exploited to hack WordPress sites By Bill Toulas October 6, 2026 05:00 PM 0 Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older. The Ninja Forms plugin for WordPress is installed on more than 500,000 sites and allows creating custom forms without writing code. WPC Product Bundles for WooCommerce allows storing group products into bundles and is active on more than 30,000 WordPress sites. The campaign was identified on October 4 by researchers at WordPress security platform Patchstack, against users of WPC Product Bundles for WooCommerce. The next day, the same activity was observed against Ninja Forms. In both attacks, the same JavaScript payload was delivered from ‘imgcdn1[.]com,’ indicating the same threat actor behind the exploitation attempts against the two plugins. According to the researchers, the attacker tries to plant malicious JavaScript (x.js) in WooCommerce order data or Ninja Forms submissions. When a logged-in administrator loads the content, the script executes using the authenticated WordPress session. When launched, it retrieves the necessary administrative nonces and uses legitimate WordPress functions to install a malicious plugin masquerading as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs” and create an administrator account. At that stage, the JavaScript payload and the malicious plugin’s PHP scripts establish four access mechanisms to the compromised site: A visible administrator account An administrator account concealed from the WordPress user list in the dashboard A secret login URL that authenticates as the site’s oldest existing administrator An unauthenticated file manager accessible through a direct request to the malicious plugin’s main PHP file The file manager can't execute commands, but it could still be used to introduce additional payloads on the site. Even if the WP Smart Thumbnails plugin is removed from the infected website, the hidden account and secret login URL continue to function as persistence mechanisms through separate auxiliary attack plugins featuring backdated timestamps to evade detection. “The [hidden] account does not appear in Users → All Users, does not appear in the Administrator filter, and is not counted in the totals above the list,” Patchstack explains, adding that “It is a fully privileged administrator the site owner cannot see.” Patchstack says that exploitation is currently limited, but advises site admins to upgrade to the latest versions of the affected plugins, WPC Product Bundles for WooCommerce version 8.6.7 or later and Ninja Forms 3.15.4 or later. Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection. Administrators are strongly recommended to check for signs of compromise. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Hackers target WordPress sites via third-party WooCommerce pluginCritical Elementor Pro flaw exploited to take over WordPress sitesHackers target WordPress sites in miniOrange auth bypass attacksWordPress membership plugin bug exploited to create admin accountsMicrosoft says threat actors are ahead in the early AI race

Indicators of Compromise

  • malware — WP Smart Thumbnails
  • cve — CVE-2026-93836
  • cve — CVE-2026-94504

Entities

Ninja Forms (product)WPC Product Bundles for WooCommerce (product)WordPress (technology)WooCommerce (technology)