Hackers exploit Ninja Forms and WooCommerce plugin XSS flaws to plant hidden WordPress admins

Patchstack says a single campaign is abusing stored XSS bugs in Ninja Forms and WPC Product Bundles to create admin accounts, a magic login link and a file manager backdoor.

Hackers exploit Ninja Forms and WooCommerce plugin XSS flaws to plant hidden WordPress admins

At a glance

  • CVE-2026-94504 (Ninja Forms up to 3.15.3) and CVE-2026-93836 (WPC Product Bundles up to 8.6.6) are being exploited.
  • The script runs in an administrator's browser session and installs a malicious plugin called WP Smart Thumbnails.
  • Attackers leave four ways back in, including a hidden admin account and a token-based login URL.
  • Updating stops new attacks but does not remove an existing infection, Patchstack warns.

Attackers are exploiting two unauthenticated stored cross-site scripting (XSS) vulnerabilities in popular WordPress plugins to take over sites and leave multiple backdoors behind, according to WordPress security firm Patchstack. The flaws, CVE-2026-94504 in Ninja Forms and CVE-2026-93836 in WPC Product Bundles for WooCommerce, were publicly disclosed on September 22, and exploitation began in early October. BleepingComputer reports that Ninja Forms is installed on more than 500,000 sites and WPC Product Bundles on more than 30,000.

What happened

Patchstack says it first observed the campaign on October 4 at 10:39 UTC against WPC Product Bundles, and that the same payload was deployed against Ninja Forms the following day, indicating a single operator behind both waves. According to the researchers, the attack infrastructure domain imgcdn1.com was registered on October 1, days before the first attacks.

The attacker plants malicious JavaScript in WooCommerce order data or in Ninja Forms submissions. When a site administrator later views that content in the dashboard, the script runs inside the administrator's authenticated session. Patchstack notes that the code does not need to steal passwords: it reuses the session cookies the browser already sends and scrapes the security nonces WordPress uses to authorize admin actions.

Technical details

Both bugs carry a CVSS score of 7.1, Patchstack said. In WPC Product Bundles, quantity parameters beginning with numbers could pass validation while still carrying attacker markup into order metadata. In Ninja Forms, textarea submissions were rendered without proper HTML encoding in the legacy admin editor.

Once running, the script contacts a command server, installs a malicious plugin named WP Smart Thumbnails (wp-smart-thumbnails, presented as version 1.2.4) and fetches a persistence installer. Patchstack describes four ways the attacker keeps access: a visible administrator account with names such as support, updater, maintenance or backup and an @wordpress.org email address; a second administrator hidden from the Users screen through must-use plugin hooks; a magic login link at /wp-login.php?_wplogin=<token> that signs the holder in as the site's original owner; and a file manager with no authentication. The researchers also warn that the installer deliberately backdates the files it writes, so modification times cannot be trusted.

Who is affected

Sites running Ninja Forms 3.15.3 or older, or WPC Product Bundles for WooCommerce 8.6.6 or older, are vulnerable. Patchstack lists imgcdn1.com, /fz/x.js and /fz/c.php as key network indicators, along with the fz_emer_done_v1 and fz_emer_login_tokens database options and files such as /wp-content/mu-plugins/class-wp-token-validate.php.

What to do

Administrators should update Ninja Forms to 3.15.4 or later and WPC Product Bundles to 8.6.7 or later. Patchstack stresses that updating "does not clean an existing infection." It recommends searching logs for the indicators above, querying the database directly for administrator accounts and comparing the result with what the dashboard shows, removing unknown accounts, plugins and must-use files, clearing the two options, rotating all administrator passwords and authentication salts, and treating the oldest administrator account as compromised.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.