Attackers are exploiting stored cross-site scripting flaws in the Ninja Forms and WPC Product Bundles for WooCommerce plugins to take over WordPress sites. The two plugins run on more than 500,000 and more than 30,000 sites respectively, according to Patchstack, the security firm that tracked the campaign.
Two WordPress Plugin Flaws Exploited in Back-to-Back Attacks
Patchstack identified exploitation of WPC Product Bundles on October 4 and the same activity against Ninja Forms on October 5. Public reporting followed on October 6. Both flaws are rated high severity and both are stored XSS bugs, meaning attacker-supplied script is saved by the site and runs later in another user’s browser.
CVE-2026-94504 in Ninja Forms
CVE-2026-94504 affects Ninja Forms versions 3.15.3 and older. The plugin is installed on more than 500,000 sites. The vendor fixed the flaw in version 3.15.4. Attackers reach the vulnerable code by submitting forms that carry the malicious script.
CVE-2026-93836 in WPC Product Bundles for WooCommerce
CVE-2026-93836 affects WPC Product Bundles for WooCommerce versions 8.6.6 and older, which are installed on more than 30,000 sites. The fix is in version 8.6.7. In this case the script arrives through WooCommerce orders rather than form entries.
How the Attack Chain Works
The attacker delivers JavaScript hosted on imgcdn1[.]com by placing it in a WooCommerce order or a form submission. Nothing happens at the moment of submission. The script runs when a site administrator later views the stored content in the WordPress dashboard.
Because the code executes in the administrator’s logged-in browser session, it can act with administrator rights. The script uses that position to install a fake plugin named “WP Smart Thumbnails.”
Four Persistence Mechanisms in the Fake WP Smart Thumbnails Plugin
The fake plugin gives attackers four separate ways back into a compromised site:
- A visible administrator account.
- A hidden administrator account.
- A secret login URL.
- An unauthenticated file manager.
Having four independent footholds means that removing one of them does not by itself end the attacker’s access. A site owner who finds and deletes the visible account would still face the hidden account, the secret login address and the file manager, any of which could be used to regain control.
Scope and Patch Status
Patchstack’s findings point to full site takeover with hidden persistence on potentially tens of thousands of sites, given the install bases of the two plugins. The exact number of compromised sites has not been published.
Patches are available for both plugins. Ninja Forms 3.15.4 fixes CVE-2026-94504, and WPC Product Bundles 8.6.7 fixes CVE-2026-93836. The campaign runs on the same pattern against both plugins: submit malicious content, wait for an administrator to view it, then install the backdoor plugin.
Sequence of the Two Campaigns
Patchstack saw exploitation of the smaller plugin first, on October 4, and the same activity against the larger plugin the next day, on October 5. Both campaigns deliver script from imgcdn1[.]com and install the same fake plugin.
Sites that run either plugin at the affected versions are exposed to the stored XSS path. Sites where the fake plugin has already been installed carry the four persistence mechanisms described above regardless of whether the original plugin has since been updated, because the backdoor accounts and file manager are separate from the vulnerable code that delivered them.
What Is Known and What Is Not
The reporting establishes the two CVE identifiers, the affected and fixed versions, the delivery domain, and the structure of the fake plugin. It does not provide a count of confirmed victim sites, and it does not identify the operators behind the campaign.
Indicators named in the reporting are the “WP Smart Thumbnails” plugin, unexpected administrator accounts, and the imgcdn1[.]com script host. Both vendors have shipped fixes, so the open question is how many sites were reached before updates were applied.
