Ninja Forms plugin flaw exploited to hack WordPress sites
Description
Stored cross-site scripting (XSS) vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins are being exploited to install backdoors and create rogue administrator accounts. The attacks deliver malicious JavaScript payloads that execute in the context of authenticated administrators, allowing the installation of a malicious plugin and creation of hidden admin accounts. These backdoors persist even after removal of the malicious plugin. The vulnerabilities require an authenticated session to exploit and affect Ninja Forms versions 3.15.3 and older and WPC Product Bundles for WooCommerce versions 8.6.6 and older. Site administrators are advised to upgrade to Ninja Forms 3.15.4 or later and WPC Product Bundles for WooCommerce 8.6.7 or later. Existing infections require manual cleanup as updates do not remove backdoors.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Hackers are exploiting stored XSS vulnerabilities tracked as CVE-2026-94504 (Ninja Forms) and CVE-2026-93836 (WPC Product Bundles for WooCommerce) to deliver malicious JavaScript payloads via form submissions or WooCommerce order data. The payload executes in the context of logged-in administrators, retrieves administrative nonces, and uses legitimate WordPress functions to install a malicious plugin named “WP Smart Thumbnails” version 1.2.4. This plugin creates multiple backdoors including visible and hidden administrator accounts, a secret login URL authenticating as the oldest admin, and an unauthenticated file manager. The hidden admin account is not visible in the WordPress user list or admin filters, enabling persistent unauthorized access. The malicious plugin and auxiliary backdoor plugins use backdated timestamps to evade detection. Exploitation requires an authenticated session and is currently limited. The vulnerabilities affect Ninja Forms versions 3.15.3 and older and WPC Product Bundles for WooCommerce versions 8.6.6 and older. Patchstack researchers identified the campaign in early October 2026. Upgrading to Ninja Forms 3.15.4 or later and WPC Product Bundles 8.6.7 or later prevents further exploitation but does not remove existing backdoors.
Potential Impact
Successful exploitation allows attackers to install persistent backdoors on WordPress sites, including hidden administrator accounts and secret login mechanisms, enabling full site compromise. Attackers can maintain long-term unauthorized access even after removal of the malicious plugin. The unauthenticated file manager allows uploading additional payloads, increasing the risk of further compromise. The vulnerabilities require an authenticated session, limiting exploitation to users with some level of access, but the impact is severe due to the persistence and stealth of the backdoors.
Mitigation Recommendations
Site administrators should immediately upgrade Ninja Forms to version 3.15.4 or later and WPC Product Bundles for WooCommerce to version 8.6.7 or later to prevent further exploitation. These updates address the stored XSS vulnerabilities. However, updating does not remove existing infections; administrators must manually inspect for and remove malicious plugins, hidden administrator accounts, secret login URLs, and other backdoors. Monitoring for unusual administrator accounts and unauthorized plugins is recommended. Follow vendor advisories and Patchstack guidance for detailed cleanup procedures.
Technical Details
- Classification
- {"confidence":0.69,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/","fetched":true,"fetchedAt":"2026-10-06T21:03:20.744Z","wordCount":796}
Threat ID: 6ac5621a2cdf04f656de8b65
Added to database: 10/06/2026, 21:03:22 UTC
Last enriched: 10/06/2026, 21:03:29 UTC
Last updated: 10/06/2026, 21:48:22 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.