Hackers are actively exploiting stored cross-site scripting (XSS) vulnerabilities in two WordPress plugins to compromise websites, install backdoors, and create unauthorized administrator accounts.

The vulnerabilities affect Ninja Forms and WPC Product Bundles for WooCommerce. They are tracked as CVE-2026-94504 in Ninja Forms versions 3.15.3 and older, and CVE-2026-93836 in WPC Product Bundles for WooCommerce versions 8.6.6 and older. Both vulnerabilities have been rated high severity and require an authenticated user session to exploit.

Ninja Forms is installed on more than 500,000 WordPress websites and allows users to build custom forms without coding. WPC Product Bundles for WooCommerce, meanwhile, is active on more than 30,000 sites and lets WooCommerce store owners group products into bundles.

Researchers at WordPress security platform Patchstack first identified the attacks on October 4 targeting WPC Product Bundles for WooCommerce users. Similar activity targeting Ninja Forms was detected the following day. Both campaigns used the same JavaScript payload hosted on imgcdn1[.]com, suggesting that the attacks are being carried out by the same threat actor.

The attackers attempt to inject a malicious JavaScript file called x.js into WooCommerce order data or Ninja Forms submissions. When a logged-in administrator views the infected content, the JavaScript executes within their authenticated WordPress session.

The payload then retrieves the required WordPress administrative nonces and abuses legitimate WordPress functionality to install a malicious plugin called “WP Smart Thumbnails” version 1.2.4, supposedly developed by “MediaPress Labs.” It also creates a new administrator account on the compromised website.

READ
Musician Sentenced After AI Bots Generated $10 Million in Fake Streaming Royalties

Once installed, the malicious code provides several ways for attackers to maintain access. These include a visible administrator account, a hidden administrator account that does not appear in the normal WordPress user list, a secret login URL that can authenticate as the site’s oldest administrator, and an unauthenticated file manager accessible directly through the malicious plugin’s PHP file.

Although the file manager cannot execute commands directly, attackers could potentially use it to upload additional malicious files or payloads. Removing the fake WP Smart Thumbnails plugin alone may also fail to completely clean an infected website because the hidden account and secret login mechanism can remain active through additional malicious plugins designed to maintain persistence.

Patchstack warns that the hidden administrator account can remain invisible in the WordPress dashboard, including under Users → All Users and the Administrator filter, while still having full administrator privileges.


Buy ExpressVPN with PayPal or Credit Card

Administrators should update WPC Product Bundles for WooCommerce to version 8.6.7 or later and Ninja Forms to version 3.15.4 or later. However, installing the latest versions only prevents further exploitation and does not remove an existing infection. Website owners should also investigate their sites for unauthorized administrator accounts, unfamiliar plugins, suspicious files and other signs of compromise.

Advertisement