Hackers Exploit WordPress Plugin XSS Flaws to Install Backdoors

Summary
Attackers are exploiting authenticated stored XSS flaws in Ninja Forms and WPC Product Bundles for WooCommerce to create rogue admin accounts and install backdoors. Updates are available, but they do not remove existing infections.
Key points
- The exploited flaws are CVE-2026-93836 in WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504 in Ninja Forms versions 3.15.3 and older.
- Both attacks use malicious JavaScript delivered from imgcdn1[.]com and require an authenticated session; the script runs when a logged-in administrator views affected content.
- The payload uses WordPress administrative nonces and functions to install a malicious plugin disguised as “WP Smart Thumbnails” and create an administrator account.
- The attackers establish multiple access paths, including a hidden administrator account, a secret login URL, and an unauthenticated file manager.
- Removing the malicious plugin may not eliminate persistence: hidden accounts and secret login access can remain through separate auxiliary plugins.
- Patchstack reported exploitation as limited. Update WPC Product Bundles to version 8.6.7 or later and Ninja Forms to version 3.15.4 or later, then check for signs of compromise.
Article Details
- Vulnerability Types
- Stored cross-site scripting (XSS)
- Severity
- High
- Affected Versions
- WPC Product Bundles for WooCommerce 8.6.6 and older
- Ninja Forms 3.15.3 and older
- Exploitation Status
- active
- Exploit Availability
- unknown
- Patch Status
- available
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | imgcdn1[.]com | Domain delivering the JavaScript payload used in exploitation of both plugins. |
MITRE ATT&CK
T1036 · MasqueradingThe malicious plugin masquerades as WP Smart Thumbnails version 1.2.4 from MediaPress Labs.T1059.007 · JavaScriptMalicious JavaScript planted in order data or form submissions executes when a logged-in administrator loads the content.T1070.006 · TimestompAuxiliary attack plugins have backdated timestamps to evade detection.T1136 · Create AccountThe payload creates administrator accounts on compromised WordPress sites, including one concealed from the dashboard user list.T1505 · Server Software ComponentThe attacker installs a malicious WordPress plugin and separate auxiliary plugins that maintain access to the site.
CVE
CVE-2026-93836They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.CVE-2026-94504They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
Malware
Products
Ninja FormsNinja Forms plugin flaw exploited to hack WordPress sitesWooCommerceHackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.WordPressNinja Forms plugin flaw exploited to hack WordPress sitesWPC Product Bundles for WooCommerceHackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.