chiprook
← Security
SecurityOctober 7, 2026, 04:00

Hackers exploit Ninja Forms and WPC Product Bundles plugin flaws on WordPress

Attackers are exploiting stored XSS vulnerabilities in WordPress plugins Ninja Forms (CVE-2026-94504, versions 3.15.3 and older) and WPC Product Bundles for WooCommerce (CVE-2026-93836, versions 8.6.6 and older) to install backdoors and create hidden admin accounts. Ninja Forms runs on over 500,000 sites and WPC Product Bundles on over 30,000. Fixes are available in versions 3.15.4 and 8.6.7.

Hackers exploit Ninja Forms and WPC Product Bundles plugin flaws on WordPress
#WordPress#NinjaForms#WooCommerce
Read next
Security

Hackers target WordPress sites via third-party WooCommerce plugin

Business

Automattic has a new board after failed attempt to oust CEO

Security

Four WordPress plugins hit by CVSS 9.8 auth bypass flaws

Security

CVE-2026-12227: Critical unauthenticated LFI in Visual Composer WordPress plugin