
A serious security flaw in the Ninja Forms and WPC Product Bundles for WooCommerce plugins is currently being exploited by hackers to gain unauthorized access to WordPress sites. This issue arises from stored cross-site scripting (XSS) vulnerabilities, which allow attackers to install backdoors and create unauthorized admin accounts.
The vulnerabilities, known as CVE-2026-93836 for WPC Product Bundles affecting versions up to 8.6.6, and CVE-2026-94504 for Ninja Forms affecting versions up to 3.15.3, pose a significant risk. The Ninja Forms plugin is widely used, installed on over 500,000 sites, enabling users to create custom forms without coding expertise.
The first signs of these attacks were noted on October 4 by Patchstack, a WordPress security platform, beginning with WPC Product Bundles. The following day, similar attacks were detected targeting Ninja Forms. Both attacks utilized a JavaScript payload delivered through the same domain, suggesting a common threat actor.
The malicious script attempts to embed itself in WooCommerce order data or Ninja Forms submissions. When an administrator logs in, the script activates, leveraging their session to install a harmful plugin disguised as “WP Smart Thumbnails” and create an unauthorized administrator account.
This new account allows the hacker multiple access points:
- A visible admin account.
- A hidden admin account not listed in the user dashboard.
- A secret login URL that connects to the site’s most senior existing administrator.
- A file manager that can be accessed without authentication through a direct link to the malicious plugin.
Although this file manager lacks command execution capabilities, it can still facilitate further attacks by delivering additional malicious payloads.
Even if the harmful plugin is removed, the hidden account and secret URL remain active, allowing hackers continued access through other auxiliary plugins tailored to avoid detection. Patchstack notes that the hidden account does not show up in the user list, making it quite the elusive intruder.
Currently, the scale of exploitation is said to be limited, but site administrators are advised to update to the latest versions of the affected plugins—WPC Product Bundles for WooCommerce version 8.6.7 or newer, and Ninja Forms version 3.15.4 or newer. While patching the vulnerable plugins curbs further exploitation, it does not remedy existing infections. Administrators are encouraged to examine their sites for any signs of compromise.
