Hackers exploit Ninja Forms and WPC Product Bundles plugin flaws on WordPress
Attackers are exploiting stored XSS vulnerabilities in WordPress plugins Ninja Forms (CVE-2026-94504, versions 3.15.3 and older) and WPC Product Bundles for WooCommerce (CVE-2026-93836, versions 8.6.6 and older) to install backdoors and create hidden admin accounts. Ninja Forms runs on over 500,000 sites and WPC Product Bundles on over 30,000. Fixes are available in versions 3.15.4 and 8.6.7.
- CVE-2026-94504 affects Ninja Forms 3.15.3 and older, CVE-2026-93836 affects WPC Product Bundles 8.6.6 and older
- Exploitation requires an authenticated session and delivers JavaScript from imgcdn1[.]com
- The script installs a WP Smart Thumbnails plugin and creates a hidden administrator
- Fixes: Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7
Read next
Security