Attackers are exploiting high-severity stored cross-site scripting flaws in two WordPress plugins to install backdoors and create rogue administrator accounts. The vulnerabilities affect Ninja Forms 3.15.3 and earlier (CVE-2026-94504) and WPC Product Bundles for WooCommerce 8.6.6 and earlier (CVE-2026-93836). Exploitation requires an authenticated session: attackers embed malicious JavaScript in form submissions or WooCommerce order data, which executes with a logged-in administrator’s privileges when the administrator views the content. Patchstack observed attacks on October 4 and 5; a shared JavaScript payload suggests the same threat actor, although observed exploitation remains limited in scale.
The payload abuses the administrator’s session to install a malicious plugin and establish persistent access through hidden administrator accounts, a secret login URL, and auxiliary plugins with backdated file timestamps. Administrators should update Ninja Forms to 3.15.4 or later and WPC Product Bundles to 8.6.7 or later, then separately investigate unauthorized administrator accounts, suspicious plugins, and other persistence mechanisms. Updating the vulnerable plugins closes the flaws but does not remove backdoors or remediate existing compromises.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
On October 5, Patchstack observed attacks exploiting CVE-2026-94504 in Ninja Forms versions 3.15.3 and earlier through malicious form submissions. Both plugin attacks delivered the same JavaScript payload from imgcdn1[.]com, suggesting a shared threat actor.
On October 4, Patchstack identified attacks exploiting CVE-2026-93836, a stored cross-site scripting flaw affecting WPC Product Bundles for WooCommerce versions 8.6.6 and earlier. Attackers planted malicious JavaScript in order data to execute within an administrator's authenticated session.
Patchstack detailed how the payload installs a malicious plugin masquerading as WP Smart Thumbnails and establishes visible and hidden administrator accounts, a secret login URL, and an unauthenticated file manager, with auxiliary plugins maintaining persistence. It advised updating both vulnerable plugins and separately investigating compromise because updates do not remove existing infections.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
cert.ug
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.