discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored XSS vulnerabilities in Ninja Forms and WPC Product Bundles for WooCommerce plugins to install backdoors and create rogue admin accounts on WordPress sites.

By Bill Toulas·Oct 6·bleepingcomputer.com·2 min read

Intelligence analysis by Gemini 2.5 Flash Lite

Ninja Forms plugin flaw exploited to hack WordPress sites
Image: bleepingcomputer.com

Attackers are leveraging critical vulnerabilities in popular WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to gain unauthorized access. By injecting malicious JavaScript into submissions, they can create hidden administrator accounts and install backdoors, even after the initial plugin is removed, posing a significant persistence threat.

Why it matters

This incident highlights a critical security risk for over 500,000 WordPress sites using the Ninja Forms plugin, as attackers can establish persistent backdoors and hidden administrative access, potentially leading to complete site compromise.

Imagine your website is a house. Hackers found a way to sneak a tiny, invisible note into a guestbook (the Ninja Forms plugin). When the homeowner (website admin) reads the note, it tells the hacker how to unlock a secret door and even create a fake guest who can come and go as they please, even after the note is gone.

Analysis

Ninja Forms Plugin Vulnerability

The Ninja Forms plugin, a widely used tool for creating custom forms on WordPress sites with over 500,000 installations, has been found to contain a severe stored cross-site scripting (XSS) vulnerability. This flaw, tracked as CVE-2026-94504, affects versions 3.15.3 and older. The vulnerability requires an authenticated session to be exploited, meaning an attacker must first gain some level of access to the target WordPress site. However, once exploited, it allows for the injection of malicious JavaScript code into form submissions. This code is designed to execute when a logged-in administrator views the submitted data, leveraging their authenticated session to perform malicious actions.

WPC Product Bundles for WooCommerce Exploitation

Simultaneously, a similar attack vector was identified targeting the WPC Product Bundles for WooCommerce plugin, active on over 30,000 sites. This vulnerability, identified as CVE-2026-93836, impacts versions 8.6.6 and older. Researchers at Patchstack observed the same JavaScript payload, originating from the domain 'imgcdn1[.]com,' being used in attacks against both plugins. This strongly suggests a single threat actor is behind both exploitation campaigns. The attacker's objective is to plant malicious JavaScript within order data or form submissions, which then executes when an administrator accesses this content, enabling the attacker to establish a foothold.

Persistence and Evasion Tactics

Upon successful exploitation, the injected JavaScript retrieves administrative nonces and utilizes legitimate WordPress functions to install a malicious plugin named "WP Smart Thumbnails" (version 1.2.4) and create a new administrator account. The attackers employ sophisticated persistence mechanisms, including a hidden administrator account that is not visible in the WordPress user list and a secret login URL. Even if the initially installed malicious plugin is removed, these hidden accounts and secret URLs remain functional through auxiliary attack plugins, often with backdated timestamps to evade detection. Furthermore, a file manager component within the malicious plugin, though limited in command execution, can be used to upload additional malicious payloads, underscoring the depth of potential compromise.

Key points

  • Stored XSS vulnerabilities in Ninja Forms and WPC Product Bundles for WooCommerce plugins are being actively exploited.
  • Attackers install backdoors and create hidden administrator accounts for persistent access.
  • The same JavaScript payload from 'imgcdn1[.]com' is used in attacks against both plugins.
  • Exploitation requires an authenticated session but leads to sophisticated persistence methods.
  • Website administrators are urged to update affected plugins and check for signs of compromise.
The Upside

Prompt patching of these vulnerabilities by plugin developers and swift adoption of updates by website administrators can effectively neutralize the threat, preventing further unauthorized access and data breaches. Increased awareness and proactive security audits by site owners can also help in early detection and remediation of any existing infections.

The Downside

The sophisticated persistence mechanisms, including hidden admin accounts and secret login URLs, mean that even after updating the vulnerable plugins, compromised sites may remain at risk if not thoroughly audited and cleaned. The potential for attackers to maintain long-term access could lead to significant data theft, reputational damage, and further malicious activities.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywordpresspluginsxssvulnerabilitybackdoor

Author

Bill Toulas

Intelligence analysis by

Gemini 2.5 Flash Lite

Published

Oct 6, 2026

Source

bleepingcomputer.com

Share

Topics

securitywordpresspluginsxssvulnerabilitybackdoor

Related

More from this desk

Oct 7·bleepingcomputer.com

PoeLLM malware infects exposed AI servers in cryptomining attacks

PoeLLM malware targets exposed AI servers, using a poem for C2 addresses. Researchers found 3,400 compromised servers, with activity peaking at 800 infected systems.

Oct 7·bleepingcomputer.com

Ransomware has a new target. Is your backup ready?

Ransomware groups are targeting backups, making them a new threat. IT leaders need to secure their backups to prevent data loss.

Oct 7·krebsonsecurity.com

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

Jordanian teenager detained for leading ShinyHunters, a data theft and extortion group. FBI investigating extortion of Boeing subsidiary Jeppesen ForeFlight.

Oct 7·schneier.com

Apple’s Verified Photography System

Apple introduces a new system called 'Reference Image' to verify iPhone photos without tying them to specific devices or photographers.