MikhbarMIKHBAR
Automation

Ninja Forms and WooCommerce Plugins Hit by Exploitation Campaign

A newly uncovered active exploitation campaign targets high-severity stored cross-site scripting vulnerabilities in two popular WordPress plugins, leaving compromised sites with hidden administrator accounts and multiple backdoors.

Ninja Forms and WooCommerce Plugins Hit by Exploitation Campaign

Active Exploitation Targeting WordPress Plugins

Hackers have begun exploiting stored cross-site scripting (XSS) vulnerabilities across two unrelated WordPress plugins: Ninja Forms and WPC Product Bundles for WooCommerce. As reported by <a href="https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/">BleepingComputer</a>, the ongoing campaign is designed to install backdoors and create rogue administrator accounts on vulnerable installations. Further details are available from BleepingComputer in the original source material.

Both security flaws carry a high severity score and require an authenticated session to successfully exploit. The issues are officially tracked as CVE-2026-93836, which affects WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, impacting Ninja Forms versions 3.15.3 and older.

The Ninja Forms plugin is installed on more than 500,000 active websites, enabling users to build custom forms without needing to write code. Meanwhile, WPC Product Bundles for WooCommerce allows administrators to store grouped products into bundles and is currently active on more than 30,000 WordPress sites.

Discovery and Attack Mechanics

Researchers at the WordPress security platform Patchstack first identified the campaign on October 4 targeting users of WPC Product Bundles for WooCommerce. The very next day, identical malicious activity was observed targeting Ninja Forms installations.

In both attack vectors, the exact same JavaScript payload was delivered from the domain 'imgcdn1[.]com', pointing directly to a single threat actor behind the exploitation attempts against both plugins. According to <a href="https://www.bleepingcomputer.com/author/bill-toulas/">Bill Toulas</a>, the attacker attempts to plant malicious JavaScript code named x.js into WooCommerce order data or Ninja Forms submissions.

Once a logged-in site administrator loads the affected content, the injected script executes utilizing the active authenticated WordPress session. Upon launching, it retrieves the necessary administrative nonces and leverages legitimate WordPress functions to install a malicious plugin disguised as "WP Smart Thumbnails" version 1.2.4 from "MediaPress Labs", while simultaneously creating a new administrator account.

Establishing Multi-Layered Backdoors and Persistence

At that stage of the attack, the deployed JavaScript payload alongside the malicious plugin's PHP scripts successfully establishes four distinct access mechanisms to the compromised WordPress site. These mechanisms are structured to maintain persistent access even if basic cleanup attempts are made.

The primary persistence method involves an administrator account that is entirely concealed from the standard WordPress user list within the dashboard. Detailed insight regarding these techniques is available when <a href="https://patchstack.com/articles/four-ways-back-in-the-wordpress-xss-campaign-that-hides-its-own-admin-account/">Patchstack explains</a> how the campaign maintains its grip on targeted servers.

In addition to the hidden user account, the attackers establish a secret login URL that authenticates automatically as the site's oldest existing administrator. Furthermore, an unauthenticated file manager is made accessible via a direct request to the malicious plugin's main PHP file. While this file manager cannot directly execute commands, it provides an avenue to introduce additional payloads onto the server.

Evasion Techniques and Dashboard Invisibility

Even if the visible WP Smart Thumbnails plugin is manually removed from an infected website, the hidden administrator account and the secret login URL continue to function smoothly. They maintain persistence through separate auxiliary attack plugins that feature backdated timestamps specifically designed to evade detection by standard security audits.

Highlighting the stealthy nature of the rogue account, Patchstack notes that the hidden profile does not appear under Users, All Users, or the Administrator filter, and is completely omitted from the total counts displayed above the user list. It operates as a fully privileged administrator that the site owner cannot visually verify within the dashboard interface.

Recommended Remediation and Mitigation Steps

Although Patchstack reports that current exploitation remains limited, site administrators are strongly advised to take immediate action. Operators must upgrade their installations to the latest patched versions of the affected software: WPC Product Bundles for WooCommerce version 8.6.7 or later, and Ninja Forms version 3.15.4 or later.

Security analysts emphasize that simply updating a vulnerable plugin only prevents future exploitation; it does not clean an already existing infection. Because auxiliary plugins and hidden accounts can linger, administrators are strongly urged to perform thorough forensic checks for any signs of prior compromise.

Sources

Continue chronologically

You are readingNinja Forms and WooCommerce Plugins Hit by Exploitation Campaign
Google Narrows Open Source Bug Bounty Amid Invalid Reports
Older storyGoogle Narrows Open Source Bug Bounty Amid Invalid ReportsOctober 5, 2026 · 3 min