Product
WooCommerce
- First Reported
- Oct 6, 2026
- Latest Reported
- Oct 6, 2026
Reported Context (1)
- Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. Hackers Exploit WordPress Plugin XSS Flaws to Install Backdoors
CVE (2)
Malware (1)
MITRE ATT&CK (5)
Products (3)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.