Ninja Forms plugin flaw exploited to hack WordPress sites

Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.

Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.

The Ninja Forms plugin for WordPress is installed on more than 500,000 sites and allows creating custom forms without writing code.

WPC Product Bundles for WooCommerce allows storing group products into bundles and is active on more than 30,000 WordPress sites.

The campaign was identified on October 4 by researchers at WordPress security platform Patchstack, against users of WPC Product Bundles for WooCommerce. The next day, the same activity was observed against Ninja Forms.

In both attacks, the same JavaScript payload was delivered from ‘imgcdn1[.]com,’ indicating the same threat actor behind the exploitation attempts against the two plugins.

According to the researchers, the attacker tries to plant malicious JavaScript (x.js) in WooCommerce order data or Ninja Forms submissions. When a logged-in administrator loads the content, the script executes using the authenticated WordPress session.

When launched, it retrieves the necessary administrative nonces and uses legitimate WordPress functions to install a malicious plugin masquerading as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs” and create an administrator account.

At that stage, the JavaScript payload and the malicious plugin’s PHP scripts establish four access mechanisms to the compromised site:

  1. A visible administrator account
  2. An administrator account concealed from the WordPress user list in the dashboard
  3. A secret login URL that authenticates as the site’s oldest existing administrator
  4. An unauthenticated file manager accessible through a direct request to the malicious plugin’s main PHP file

The file manager can't execute commands, but it could still be used to introduce additional payloads on the site.

Even if the WP Smart Thumbnails plugin is removed from the infected website, the hidden account and secret login URL continue to function as persistence mechanisms through separate auxiliary attack plugins featuring backdated timestamps to evade detection.

“The [hidden] account does not appear in Users → All Users, does not appear in the Administrator filter, and is not counted in the totals above the list,” Patchstack explains, adding that “It is a fully privileged administrator the site owner cannot see.”

Patchstack says that exploitation is currently limited, but advises site admins to upgrade to the latest versions of the affected plugins, WPC Product Bundles for WooCommerce version 8.6.7 or later and Ninja Forms 3.15.4 or later.

Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection. Administrators are strongly recommended to check for signs of compromise.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Dive deeper

Free tools to verify and analyze what this article covers:

source: BleepingComputer