Computers

Patchstack Flags WordPress Plugin XSS Attacks Installing Backdoors

Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to plant backdoors and rogue admin accounts on WordPress sites.

Researchers at Patchstack have identified an active exploitation campaign targeting stored cross-site scripting vulnerabilities in two WordPress plugins: Ninja Forms and WPC Product Bundles for WooCommerce. The flaws, tracked as CVE-2026-93836 and CVE-2026-94504, are being used to install backdoors and create rogue administrator accounts on affected sites, according to bleepingcomputer.com.

The vulnerability in WPC Product Bundles for WooCommerce affects versions 8.6.6 and older, while the Ninja Forms flaw impacts versions 3.15.3 and older. Patchstack researchers first spotted the campaign on October 4 against WPC Product Bundles users, then observed the same activity against Ninja Forms the following day. Both attacks delivered the same JavaScript payload from the domain 'imgcdn1[.]com'.

In the attack chain, the attacker plants malicious JavaScript (x.js) into WooCommerce order data or Ninja Forms submissions. That script executes when a logged-in administrator views the compromised content. It then installs a plugin disguised as 'WP Smart Thumbnails' version 1.2.4 from 'MediaPress Labs' and creates an administrator account.

The attack establishes four access mechanisms on a compromised site: a visible administrator account, a concealed administrator account, a secret login URL, and an unauthenticated file manager.

Site administrators are urged to update WPC Product Bundles for WooCommerce to version 8.6.7 or later and Ninja Forms to version 3.15.4 or later. Updating the vulnerable plugin prevents further exploitation, but it does not clean an existing infection. WPC Product Bundles for WooCommerce is active on more than 30,000 WordPress sites, and Ninja Forms is installed on more than 500,000 sites, according to background data provided by the researchers.

Quick answers

Which WordPress plugins are affected by the vulnerability?

Ninja Forms versions 3.15.3 and older and WPC Product Bundles for WooCommerce versions 8.6.6 and older.

How do I protect my site from this exploit?

Update WPC Product Bundles for WooCommerce to 8.6.7 or later and Ninja Forms to 3.15.4 or later. Note that updating does not remove an existing infection.

What does the attack do once it exploits the flaw?

It installs a fake plugin called 'WP Smart Thumbnails' from 'MediaPress Labs' and creates a visible administrator account, a concealed administrator account, a secret login URL, and an unauthenticated file manager.

Source