SECURITY researchers say two unauthenticated stored XSS flaws in Ninja Forms and WPC Product Bundles for WooCommerce are being used in a WordPress campaign to plant hidden administrator accounts and persist backdoors. The flaws, CVE-2026-94504 (Ninja Forms) and CVE-2026-93836 (WPC Product Bundles), enable attackers to inject malicious scripts via form submissions or order data that render when an admin views entries.
The exploitation has been observed in the wild, with Patchstack noting payloads appeared against WPC Product Bundles on 4 October 2026 and against Ninja Forms the following day. Both plugins are widely used, with Ninja Forms reported to have over 500,000 active installations and WPC Product Bundles more than 30,000; each CVSSv3 score is 7.2.
The attack runs entirely within an administrator’s browser and does not require stealing cookies. Once the script executes, it reuses the current WordPress session by obtaining security tokens and performing privileged actions, bypassing HttpOnly cookie protections.
In its final stages, the payload installs four backdoors: a fake plugin named WP Smart Thumbnails, a direct-access unauthenticated file manager, must-use plugins to hide another admin account from Users, and a “magic login” link that silently authenticates anyone using it. The two loaders fetch a common second-stage script from the attacker’s server, linking the campaigns to a single operation even though multiple entry points exist.
Upstream advisories urge upgrading Ninja Forms to 3.15.4+ and WPC Product Bundles to 8.6.7+ and performing thorough compromise hunting, including log and plugin searches for indicators such as imgcdn1[.]com and wp-smart-thumbnails.