Hackers exploit Ninja Forms and WooCommerce plugin XSS flaws to plant hidden WordPress admins
Patchstack says a single campaign is abusing stored XSS bugs in Ninja Forms and WPC Product Bundles to create admin accounts, a magic login link and a file manager backdoor.
