Patchstack caught a live campaign abusing stored cross-site scripting in two unrelated WordPress plugins. The same JavaScript, loaded from imgcdn1[.]com, installs a backdoor and an administrator the site owner cannot see in the user list.
What happened
The flaws are CVE-2026-94504 in Ninja Forms 3.15.3 and older, and CVE-2026-93836 in WPC Product Bundles for WooCommerce 8.6.6 and older. Both need an authenticated session. The attacker plants script in a form submission or in WooCommerce order data. The payload runs when a logged-in administrator opens that content.
Patchstack saw the WooCommerce plugin hit on 4 October 2026 and Ninja Forms the next day. The script pulls admin nonces and uses normal WordPress functions to install a fake plugin, WP Smart Thumbnails 1.2.4, attributed to MediaPress Labs, and to create an administrator.
Persistence is four paths: a visible admin, a hidden admin that does not appear under Users, a secret login URL that authenticates as the oldest existing administrator, and an unauthenticated file manager in the malicious plugin. Removing WP Smart Thumbnails is not enough. The hidden account and secret login survive through separate auxiliary plugins with backdated timestamps.
Who is affected
Ninja Forms is installed on more than 500,000 sites. WPC Product Bundles for WooCommerce is active on more than 30,000. Exploitation so far looks limited, but any site still on the vulnerable versions is exposed the next time an administrator views poisoned content.
What to do now
- Upgrade Ninja Forms to 3.15.4 or later and WPC Product Bundles to 8.6.7 or later, then assume a patch does not clean an existing infection.
- Look for WP Smart Thumbnails, unexpected administrators, and accounts missing from All Users that can still log in.
- Check for a recently added plugin with a backdated timestamp, and review form submissions and order notes for script tags.
- Rotate administrator passwords and invalidate sessions after you remove the backdoor.
Source: BleepingComputer, citing Patchstack. Ninja Forms plugin flaw exploited to hack WordPress sites.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- CVE-2026-21589 lets unauthenticated attackers read files on 8 Atlassian products
- Fake ChatGPT and Gemini ad portals steal Google and Okta MFA codes
- Nikkei Microsoft 365 account sent 9,000 phishing emails after takeover
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.