Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored XSS vulnerabilities in Ninja Forms and WPC Product Bundles for WooCommerce plugins to install backdoors and create rogue admin accounts on WordPress sites.
Intelligence analysis by Gemini 2.5 Flash Lite

Attackers are leveraging critical vulnerabilities in popular WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to gain unauthorized access. By injecting malicious JavaScript into submissions, they can create hidden administrator accounts and install backdoors, even after the initial plugin is removed, posing a significant persistence threat.
Imagine your website is a house. Hackers found a way to sneak a tiny, invisible note into a guestbook (the Ninja Forms plugin). When the homeowner (website admin) reads the note, it tells the hacker how to unlock a secret door and even create a fake guest who can come and go as they please, even after the note is gone.
Analysis
Ninja Forms Plugin Vulnerability
The Ninja Forms plugin, a widely used tool for creating custom forms on WordPress sites with over 500,000 installations, has been found to contain a severe stored cross-site scripting (XSS) vulnerability. This flaw, tracked as CVE-2026-94504, affects versions 3.15.3 and older. The vulnerability requires an authenticated session to be exploited, meaning an attacker must first gain some level of access to the target WordPress site. However, once exploited, it allows for the injection of malicious JavaScript code into form submissions. This code is designed to execute when a logged-in administrator views the submitted data, leveraging their authenticated session to perform malicious actions.
WPC Product Bundles for WooCommerce Exploitation
Simultaneously, a similar attack vector was identified targeting the WPC Product Bundles for WooCommerce plugin, active on over 30,000 sites. This vulnerability, identified as CVE-2026-93836, impacts versions 8.6.6 and older. Researchers at Patchstack observed the same JavaScript payload, originating from the domain 'imgcdn1[.]com,' being used in attacks against both plugins. This strongly suggests a single threat actor is behind both exploitation campaigns. The attacker's objective is to plant malicious JavaScript within order data or form submissions, which then executes when an administrator accesses this content, enabling the attacker to establish a foothold.
Persistence and Evasion Tactics
Upon successful exploitation, the injected JavaScript retrieves administrative nonces and utilizes legitimate WordPress functions to install a malicious plugin named "WP Smart Thumbnails" (version 1.2.4) and create a new administrator account. The attackers employ sophisticated persistence mechanisms, including a hidden administrator account that is not visible in the WordPress user list and a secret login URL. Even if the initially installed malicious plugin is removed, these hidden accounts and secret URLs remain functional through auxiliary attack plugins, often with backdated timestamps to evade detection. Furthermore, a file manager component within the malicious plugin, though limited in command execution, can be used to upload additional malicious payloads, underscoring the depth of potential compromise.
Key points
- Stored XSS vulnerabilities in Ninja Forms and WPC Product Bundles for WooCommerce plugins are being actively exploited.
- Attackers install backdoors and create hidden administrator accounts for persistent access.
- The same JavaScript payload from 'imgcdn1[.]com' is used in attacks against both plugins.
- Exploitation requires an authenticated session but leads to sophisticated persistence methods.
- Website administrators are urged to update affected plugins and check for signs of compromise.
Prompt patching of these vulnerabilities by plugin developers and swift adoption of updates by website administrators can effectively neutralize the threat, preventing further unauthorized access and data breaches. Increased awareness and proactive security audits by site owners can also help in early detection and remediation of any existing infections.
The sophisticated persistence mechanisms, including hidden admin accounts and secret login URLs, mean that even after updating the vulnerable plugins, compromised sites may remain at risk if not thoroughly audited and cleaned. The potential for attackers to maintain long-term access could lead to significant data theft, reputational damage, and further malicious activities.


