Hackers Exploit WordPress Plugin XSS Flaws to Install Backdoors

· Original article ↗

Summary

Attackers are exploiting authenticated stored XSS flaws in Ninja Forms and WPC Product Bundles for WooCommerce to create rogue admin accounts and install backdoors. Updates are available, but they do not remove existing infections.

Key points

  • The exploited flaws are CVE-2026-93836 in WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504 in Ninja Forms versions 3.15.3 and older.
  • Both attacks use malicious JavaScript delivered from imgcdn1[.]com and require an authenticated session; the script runs when a logged-in administrator views affected content.
  • The payload uses WordPress administrative nonces and functions to install a malicious plugin disguised as “WP Smart Thumbnails” and create an administrator account.
  • The attackers establish multiple access paths, including a hidden administrator account, a secret login URL, and an unauthenticated file manager.
  • Removing the malicious plugin may not eliminate persistence: hidden accounts and secret login access can remain through separate auxiliary plugins.
  • Patchstack reported exploitation as limited. Update WPC Product Bundles to version 8.6.7 or later and Ninja Forms to version 3.15.4 or later, then check for signs of compromise.

Article Details

Vulnerability Types
  • Stored cross-site scripting (XSS)
Severity
High
Affected Versions
  • WPC Product Bundles for WooCommerce 8.6.6 and older
  • Ninja Forms 3.15.3 and older
Exploitation Status
active
Exploit Availability
unknown
Patch Status
available

Indicators of compromise

TypeIndicatorContext
DOMAINimgcdn1[.]comDomain delivering the JavaScript payload used in exploitation of both plugins.

MITRE ATT&CK

CVE

Malware

Products

Related Articles