TL;DR
Attackers are exploiting two unauthenticated stored XSS flaws in Ninja Forms and WPC Product Bundles for WooCommerce, according to Patchstack. The WordPress XSS campaign plants a script that hijacks an administrator’s session and installs four separate backdoors, including an admin account hidden from the dashboard. Site owners should update both plugins and check for signs of compromise.
- Product: kstover Ninja Forms β Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder, wpclever WPC Product Bundles for WooCommerce
- Vulnerabilities: 2 flaws (CVE-2026-94504, CVE-2026-93836)
- Highest severity: 7.2 (High Β· CVSSv3)
- Worst impact: Ninja Forms β The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting
- Status: Exploited in the wild
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-94504 | 7.2 | CWE-79 | Exploited in the wild |
| CVE-2026-93836 | 7.2 | CWE-79 | Exploited in the wild |
Running Infra, AppSec, and SOC teams? Tag WordPress alerts by team automatically.
Try Team free for 14 daysWhy It Matters
Both plugins are widely used. Patchstack counts more than 500,000 active installations of Ninja Forms and more than 30,000 of WPC Product Bundles. Each flaw carries a CVSS score of 7.1.
The exploitation is confirmed. Patchstack says its telemetry first caught the payload on October 4, 2026, against WPC Product Bundles. The next day, the same payload arrived through Ninja Forms. The firm warns that “two is what we have confirmed, not what we expect the final count to be.”
Worse, the damage outlasts the patch. Patchstack stresses that removing the vulnerable plugin, or even the malicious one, does not close most of the backdoors this WordPress XSS campaign leaves behind.
How the Attack Works
Stored XSS as the Entry Point
Neither flaw needs a login. In WPC Product Bundles (CVE-2026-93836), a quantity field accepts a number followed by extra markup. That value lands in WooCommerce order data and later renders unsafely. In Ninja Forms (CVE-2026-94504), form submissions can render without safe encoding in the legacy admin editor.
The attacker submits malicious data and waits. When an administrator opens the order or form entry, a script loads from the attacker’s domain, imgcdn1.com. As Patchstack puts it, stored XSS “removes the hardest part of the attack: getting a privileged user to cooperate.”
Riding the Admin Session
The script never steals cookies. Instead, it runs inside the admin’s browser and reuses the live session. It grabs the security tokens that WordPress requires and performs privileged actions itself. Consequently, HttpOnly cookie protection offers no defense here.
Four Ways Back In
The script installs a fake plugin called “WP Smart Thumbnails” and creates a new administrator. The plugin hides an unauthenticated file manager that anyone can reach by direct request. A second stage then adds must-use plugins that conceal another admin account from the Users screen.
It also creates a “magic login” link. According to Patchstack, “anyone holding the URL is silently logged in as the original owner.” Finally, the malware backdates its own files so they look older than the WordPress install itself.
One Payload, Many Possible Entry Points
The two loaders differ, but they fetch the same second-stage script from the same server. That shared payload is what ties both attacks to one operation. Patchstack explains that “which plugin provides the initial XSS barely matters.” Once code runs in an admin’s browser, the rest of the chain is identical.
In other words, the attackers can add new stored XSS bugs without rebuilding their malware. Patchstack expects more plugins to join the list. Exploitation volume remains limited for now, but the firm says neither number “is a ceiling.”
Affected Versions
- Ninja Forms: through version 3.15.3 (CVE-2026-94504)
- WPC Product Bundles for WooCommerce: through version 8.6.6 (CVE-2026-93836)
Patchstack notes that both flaws were publicly disclosed on September 22. The attack domain was registered on October 1, just days before the first attempts.
Patch and Mitigation Steps
Update Both Plugins
Upgrade Ninja Forms to 3.15.4 or later. Then update WPC Product Bundles to 8.6.7, which the upstream changelog lists as the security fix.
Hunt for Compromise
Patching alone is not enough if an admin already viewed a poisoned entry. Patchstack advises these checks:
- Search web and application logs for imgcdn1.com.
- Look for a plugin with the slug wp-smart-thumbnails.
- List administrators straight from the database, then compare against the dashboard.
- Inspect the mu-plugins folder, sorting by content rather than date.
- Check wp-login.php requests for an unusual _wplogin parameter.
Patchstack warns that “a site where the XSS successfully executed in an administrator’s browser should be treated as potentially compromised.” Remove rogue accounts and files, rotate admin passwords and reset WordPress salts.
Most of the source IPs are Tor exit nodes, so blocking them will not stop this WordPress XSS campaign for long.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!