Protect.Computer
NEWS

Ninja Forms, WPC Bundles XSS Flaws Exploited to Hide WP Admins

· 2 min read · Got hacked Device safety
Ninja Forms, WPC Bundles XSS Flaws Exploited to Hide WP Admins

Patchstack, a WordPress security firm, reports that attackers are exploiting stored cross-site scripting (XSS) flaws in two unrelated plugins to take over WordPress sites: Ninja Forms, which is installed on more than 500,000 sites, and WPC Product Bundles for WooCommerce, which is active on more than 30,000. Both are rated CVSS 7.1. Exploitation was first seen on October 4 against WPC Product Bundles (CVE-2026-93836) and on October 5 against Ninja Forms (CVE-2026-94504). Both attempts pull the same JavaScript file from imgcdn1[.]com, which points to one attacker. Patchstack says exploitation is currently limited.

The attack works in two steps. The attacker plants a script in data the plugin stores: a WooCommerce order for WPC Product Bundles, or a form submission for Ninja Forms. Nothing happens until a logged-in administrator opens that order or submission. The script then runs inside the admin’s session, uses it to install a fake plugin called “WP Smart Thumbnails” 1.2.4 (“MediaPress Labs”), and creates a new administrator account. It sets up four ways back in: a visible admin account, an admin account hidden from the Users screen, a secret login URL that signs in as the site’s oldest administrator, and an unauthenticated file manager. Persistence is dropped into mu-plugins with backdated file timestamps, so removing the fake plugin alone does not evict the attacker, and a “recently modified files” search will not find the files.

How to check if you’re affected

Affected versions are Ninja Forms 3.15.3 and older, and WPC Product Bundles for WooCommerce 8.6.6 and older. Patched versions are Ninja Forms 3.15.4 or later and WPC Product Bundles 8.6.7 or later. Updating stops new attacks but does not clean a site that has already been hit, so also check for signs of compromise, especially if an administrator has opened WooCommerce orders or Ninja Forms submissions recently:

  • Look for the folder /wp-content/plugins/wp-smart-thumbnails/ and for class-wp-token-validate.php or class-wp-query-*.php in /wp-content/mu-plugins/. The Plugins screen does not list mu-plugins.
  • Search web server logs for imgcdn1.com, /fz/x.js, or requests to wp-login.php with a _wplogin parameter.
  • The hidden admin does not appear in the dashboard. Patchstack suggests querying the database for every user with the administrator capability and comparing the list to what wp-admin shows. It also suggests checking the options table for fz_emer_done_v1 and fz_emer_login_tokens.
  • If you find any of this, treat the site as compromised: remove the unknown accounts and files, delete those two options, rotate administrator passwords (including the oldest admin’s) and WordPress authentication salts.

Sources

Related reading