Full Report
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
Analysis Summary
# Vulnerability: Stored XSS in Ninja Forms and WPC Product Bundles
## CVE Details
- **CVE ID:** CVE-2026-94504 (Ninja Forms) / CVE-2026-93836 (WPC Product Bundles)
- **CVSS Score:** High Severity (Estimated 7.0 - 8.9 range)
- **CWE:** CWE-79 (Improper Neutralization of Input During Web Page Generation / Stored XSS)
## Affected Systems
- **Products:**
1. Ninja Forms (WordPress Plugin)
2. WPC Product Bundles for WooCommerce (WordPress Plugin)
- **Versions:**
1. Ninja Forms: 3.15.3 and older
2. WPC Product Bundles for WooCommerce: 8.6.6 and older
- **Configurations:** Systems where these plugins are active and allow user-submitted data (e.g., form submissions or order data).
## Vulnerability Description
Both plugins suffer from a stored Cross-Site Scripting (XSS) flaw. An attacker can inject malicious JavaScript into data fields (such as WooCommerce order data or Ninja Forms submission fields). Because the input is not properly sanitized, the script is stored on the server. When a site administrator later views the submission or order in the WordPress dashboard, the malicious script executes within the context of the administrator's authenticated session.
## Exploitation
- **Status:** Exploited in the wild (Active campaign identified October 4-5, 2026).
- **Complexity:** Medium (Requires authenticated session or public-facing form submission capability).
- **Attack Vector:** Network.
## Impact
- **Confidentiality:** High (Access to all site data and administrative functions).
- **Integrity:** High (Ability to create rogue accounts, install malicious plugins, and modify site files).
- **Availability:** High (Potential for site takeover or file deletion via unauthenticated file manager).
## Remediation
### Patches
Update to the following versions immediately:
- **Ninja Forms:** Version 3.15.4 or later.
- **WPC Product Bundles for WooCommerce:** Version 8.6.7 or later.
### Workarounds
- No specific workarounds provided; immediate patching is required as exploitation is ongoing.
- Restrict access to administrative dashboards and monitor for unusual form submission activity.
## Detection
### Indicators of Compromise
- **External Payload Source:** JavaScript loaded from `imgcdn1[.]com/x.js`.
- **Rogue Plugin:** Appearance of a plugin named **"WP Smart Thumbnails"** version 1.2.4 by "MediaPress Labs."
- **Persistence Mechanisms:**
- New administrator accounts (check database for users not visible in the dashboard).
- Backdated auxiliary attack plugins.
- Unusual PHP files acting as unauthenticated file managers.
- **Hidden Admin:** Discrepancy between the total user count and the number of visible users in the `Users -> All Users` list.
### Detection methods and tools
- **Database Audit:** Manually inspect the `wp_users` and `wp_usermeta` tables for unauthorized accounts.
- **Integrity Check:** Compare active plugins against known clean versions; check for backdated file timestamps in the `wp-content/plugins/` directory.
## References
- **Patchstack Advisory:** hxxps[://]patchstack[.]com/articles/four-ways-back-in-the-wordpress-xss-campaign-that-hides-its-own-admin-account/
- **BleepingComputer Report:** hxxps[://]www[.]bleepingcomputer[.]com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/