A new cyberattack campaign is targeting two popular WordPress plugins, exploiting stored cross-site scripting (XSS) vulnerabilities to install backdoors and create unauthorized administrator accounts . The incident is particularly significant because the attackers are not limited to executing malicious JavaScript, but are using initial access to install persistent mechanisms on already compromised websites.

Both vulnerabilities are considered high severity and require an active authenticated user session to be exploited. The first, CVE-2026-93836, affects WPC Product Bundles for WooCommerce up to version 8.6.6, while the second, CVE-2026-94504, affects Ninja Forms up to version 3.15.3.
Two plugins with a significant presence in WordPress
Ninja Forms is one of the most popular form builders for WordPress, used on over 500,000 websites. Its functionality allows administrators to create contact, registration, and data collection forms without having to write any code.
See also: Five vulnerabilities in the wolfSSH library, one critical
WPC Product Bundles for WooCommerce, on the other hand, is primarily aimed at online stores, allowing the creation of product bundles. The plugin is used on over 30,000 websites.
The wide installed base of the two plugins automatically increases interest for cybercriminals, as even a limited campaign can offer access to a significant number of potential targets.
Common infrastructure identified in attacks
The campaign was discovered on October 4 by researchers at Patchstack, who observed attacks against users of WPC Product Bundles for WooCommerce. A day later, similar activity was recorded against Ninja Forms installations.
Of particular interest is the fact that the same JavaScript payload, which was transmitted from the same server, imgcdn1[.]com. The commonality reinforces the assessment that the attacks are linked to the same perpetrator or the same operational infrastructure.
From an XSS to full site control
The dangerous element of this particular attack is the way the vulnerability is exploited. The attacker attempts to inject malicious JavaScript , named x.js , into WooCommerce order data or Ninja Forms form submissions.
When an administrator, who is already logged in to WordPress, opens this content, the malicious code is executed within the context of their active session . This allows it to exploit the privileges of that user and perform actions that normally require administrative access.
The script then retrieves the necessary WordPress nonces and uses legitimate platform functions to install a malicious plugin that appears as “WP Smart Thumbnails”, version 1.2.4, created by the alleged company “MediaPress Labs”.
See also: Pwn2Own 2026: 32 zero-day vulnerabilities on day one

Four different persistence mechanisms
The attack doesn't stop with the plugin installation. Researchers found that multiple mechanisms are created to maintain access to the compromised website.
Among other things, a normally visible administrator account, as well as a second hidden administrator account, which does not appear in the standard WordPress user list or in the relevant dashboard filters.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, a secret URL that can be used to connect with the privileges of the older administrator, while a file manager without authentication. The latter cannot execute commands directly, but can be used to place additional malicious files on the server.
Removing the plugin is not enough
One of the most worrying aspects is that deleting WP Smart Thumbnails does not necessarily mean restoring the website.
Persistence mechanisms can remain active through separate helper plugins , which are designed to make them harder to detect. In fact, researchers report that some of them use older timestamps to make them look less suspicious during a cursory inspection of the files.
This means that an administrator who simply deletes the suspicious add-on and continues to operate the site normally could leave a hidden door open to their infrastructure.
Instant upgrade for WordPress administrators
Patchstack says that active exploitation of these vulnerabilities remains limited so far, but recommends installing the patched versions.
WPC Product Bundles for WooCommerce requires version 8.6.7 or later , while Ninja Forms users should upgrade to version 3.15.4 or later .
See also: Vulnerabilities in LibreOffice and OpenOffice allow malware execution

However, the patch protects against future exploitation attempts and does not clean up a site that has already been compromised. Administrators should therefore check user accounts, installed plugins, WordPress files, and logs for suspicious activity.
In the event of a breach being detected, it is necessary to change administrative passwords, API keys, and other secrets that may have been exposed, as well as investigate possible access to customer or order data.
This campaign is a reminder that an XSS in a popular plugin is not always a “simple” browser vulnerability. When combined with an active admin session and legitimate WordPress functionality, it can turn into a full-scale site takeover mechanism. For WordPress site, timely plugin updates and regular checks for unknown accounts and files remain among the most important defenses.
source: www.bleepingcomputer.com
