Close Menu
NCIJ Network NCIJ Network
    What's Hot

    AI accelerates n-day attacks, as flaw disclosures and exploits double

    October 7, 2026

    $350M St Cloud CEO: The First Credit Union To Put Bitcoin On Core Ledger

    October 7, 2026

    Lunar Grounding Challenge – NASA

    October 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • AI accelerates n-day attacks, as flaw disclosures and exploits double
    • $350M St Cloud CEO: The First Credit Union To Put Bitcoin On Core Ledger
    • Lunar Grounding Challenge – NASA
    • 100 conservation projects are looking for funding after USAID’s closure
    • ICE Records Reveal Military Report Showing Shock Gloves Force Compliance Through Pain, Did Not Evaluate Safety
    • Unemployment and the rise of the Nazis | Nazism
    • Did Trump say of Iran, ‘Let ’em take out’ LA and San Diego?
    • David Ellison denies he has ‘politicized’ Skydance despite close Trump links | Media
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, October 7
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Ninja Forms plugin flaw exploited to hack WordPress sites

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 7, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.

    Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.

    The Ninja Forms plugin for WordPress is installed on more than 500,000 sites and allows creating custom forms without writing code.

    WPC Product Bundles for WooCommerce allows storing group products into bundles and is active on more than 30,000 WordPress sites.

    The campaign was identified on October 4 by researchers at WordPress security platform Patchstack, against users of WPC Product Bundles for WooCommerce. The next day, the same activity was observed against Ninja Forms.

    In both attacks, the same JavaScript payload was delivered from ‘imgcdn1[.]com,’ indicating the same threat actor behind the exploitation attempts against the two plugins.

    According to the researchers, the attacker tries to plant malicious JavaScript (x.js) in WooCommerce order data or Ninja Forms submissions. When a logged-in administrator loads the content, the script executes using the authenticated WordPress session.

    When launched, it retrieves the necessary administrative nonces and uses legitimate WordPress functions to install a malicious plugin masquerading as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs” and create an administrator account.

    At that stage, the JavaScript payload and the malicious plugin’s PHP scripts establish four access mechanisms to the compromised site:

    1. A visible administrator account
    2. An administrator account concealed from the WordPress user list in the dashboard
    3. A secret login URL that authenticates as the site’s oldest existing administrator
    4. An unauthenticated file manager accessible through a direct request to the malicious plugin’s main PHP file

    The file manager can’t execute commands, but it could still be used to introduce additional payloads on the site.

    Even if the WP Smart Thumbnails plugin is removed from the infected website, the hidden account and secret login URL continue to function as persistence mechanisms through separate auxiliary attack plugins featuring backdated timestamps to evade detection.

    “The [hidden] account does not appear in Users → All Users, does not appear in the Administrator filter, and is not counted in the totals above the list,” Patchstack explains, adding that “It is a fully privileged administrator the site owner cannot see.”

    Patchstack says that exploitation is currently limited, but advises site admins to upgrade to the latest versions of the affected plugins, WPC Product Bundles for WooCommerce version 8.6.7 or later and Ninja Forms 3.15.4 or later.

    Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection. Administrators are strongly recommended to check for signs of compromise.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Exploited Flaw Forms hack Ninja Plugin sites WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI accelerates n-day attacks, as flaw disclosures and exploits double

    What exactly is ISOC? And what does it mean for you?

    The AI app builder your team trusts has a root-level backdoor

    Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

    Pacing the AI frontier won’t solve agentic cybersecurity’s most urgent problems

    IANS’ Kakolowski: How AI Is Reshaping CISO Budgets

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    AI accelerates n-day attacks, as flaw disclosures and exploits double

    October 7, 2026

    $350M St Cloud CEO: The First Credit Union To Put Bitcoin On Core Ledger

    October 7, 2026

    Lunar Grounding Challenge – NASA

    October 7, 2026

    100 conservation projects are looking for funding after USAID’s closure

    October 7, 2026
    Latest Posts

    4 Best Compression Boots: Therabody, Hyperice, and More (2026)

    August 9, 2026

    Former Iraqi provincial governor arrested as graft crackdown continues | Corruption News

    August 9, 2026

    The culture surrounding ‘ideal’ childbirth has to evolve | Childbirth

    August 9, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    AI accelerates n-day attacks, as flaw disclosures and exploits double

    October 7, 2026

    $350M St Cloud CEO: The First Credit Union To Put Bitcoin On Core Ledger

    October 7, 2026

    Lunar Grounding Challenge – NASA

    October 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.