Attackers are actively exploiting stored cross-site scripting (XSS) vulnerabilities in two widely used WordPress plugins — Ninja Forms and WPC Product Bundles for WooCommerce — to establish persistent access, create rogue administrator accounts, and deploy malicious plugins.
The vulnerabilities are tracked as CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and earlier, and CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and earlier. Both flaws are rated high severity and require an authenticated session for exploitation.
WordPress XSS Flaws Target Popular Plugins
Ninja Forms is installed on more than 500,000 WordPress websites and is commonly used to build custom forms without coding. WPC Product Bundles for WooCommerce has more than 30,000 active installations and allows store owners to group products into bundled offers.
Researchers at Patchstack first observed exploitation against WPC Product Bundles for WooCommerce on October 4. Similar activity targeting Ninja Forms appeared the following day.
In both cases, the same JavaScript payload was delivered from imgcdn1[.]com, strongly suggesting that a single threat actor is behind the attacks.
Stored XSS Used to Hijack Administrator Sessions
The attack chain begins with malicious JavaScript being stored in WooCommerce order data or Ninja Forms submissions.
When a logged-in WordPress administrator later views the affected content, the payload executes inside the authenticated session. This gives the attacker access to administrative actions that would normally require valid permissions.
The malicious script retrieves WordPress security nonces and then abuses legitimate administrative functions to:
- Install a rogue plugin.
- Create new administrator accounts.
- Establish long-term persistence.
- Deploy additional access mechanisms.
Fake “WP Smart Thumbnails” Plugin Creates Backdoors
The malicious plugin is disguised as “WP Smart Thumbnails” version 1.2.4, allegedly published by “MediaPress Labs.”
Once installed, the JavaScript payload and accompanying PHP code establish multiple methods of access to the compromised site.
Researchers identified four persistence mechanisms:
- A visible administrator account.
- A hidden administrator account excluded from the standard WordPress user interface.
- A secret login URL that authenticates the attacker as the site’s oldest administrator.
- An unauthenticated file manager exposed through the malicious plugin’s PHP file.
Although the file manager does not directly provide command execution, it can still be used to upload or modify files and introduce additional malware.
Hidden Administrator Account Evades Detection
One of the most concerning elements of the campaign is the use of a concealed WordPress administrator account.
The account does not appear under the normal Users → All Users interface, is excluded from administrator filters, and is not included in displayed user totals. Despite remaining invisible to the site owner, it retains full administrative privileges.
This technique significantly complicates incident response because administrators may believe the site has been cleaned even though privileged attacker access remains active.
Removing the Malicious Plugin Is Not Enough
Deleting the fake WP Smart Thumbnails plugin does not fully remove the compromise.
Patchstack found that attackers deploy additional auxiliary plugins with manipulated timestamps, allowing the hidden administrator account and secret login mechanism to survive independently.
This means vulnerable sites may remain compromised even after the primary malicious plugin has been removed.
WordPress Administrators Should Patch and Investigate
Patchstack currently describes exploitation activity as limited, but administrators should update immediately to:
- Ninja Forms 3.15.4 or later
- WPC Product Bundles for WooCommerce 8.6.7 or later
Applying the update prevents new exploitation attempts but does not remove existing persistence.
WordPress administrators should therefore perform a full compromise assessment, including reviewing administrator accounts, installed plugins, recently modified PHP files, suspicious login mechanisms, database entries, and unexpected outbound connections.
Security teams should also inspect logs for requests associated with imgcdn1[.]com and review any unusual administrative actions performed through authenticated WordPress sessions.

Leave a Reply