Cybersecurity researchers have identified an active exploitation campaign targeting two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, leveraging stored cross-site scripting (XSS) vulnerabilities to compromise websites. The attacks, first observed on October 4 against WPC Product Bundles for WooCommerce users and then on October 5 against Ninja Forms users, involve the delivery of a consistent JavaScript payload from the domain imgcdn1[.]com, suggesting a single threat actor is behind both efforts.
The vulnerabilities, tracked as CVE-2026-94504 for Ninja Forms versions 3.15.3 and older, and CVE-2026-93836 for WPC Product Bundles for WooCommerce versions 8.6.6 and older, both carry a high severity rating and require an authenticated session for exploitation. Ninja Forms is a popular plugin used on over 500,000 WordPress sites for creating custom forms, while WPC Product Bundles for WooCommerce, active on more than 30,000 sites, facilitates grouping products into bundles.
The attack chain begins with the threat actor injecting malicious JavaScript, specifically a file named `x.js`, into WooCommerce order data or Ninja Forms submissions. When a logged-in administrator views this content, the script executes within their authenticated WordPress session. It then retrieves necessary administrative nonces and utilizes legitimate WordPress functions to install a malicious plugin, disguised as "WP Smart Thumbnails version 1.2.4 from MediaPress Labs," and simultaneously creates a new administrator account.
This process establishes four distinct access mechanisms to the compromised site. These include a visible administrator account, an administrator account that is hidden from the WordPress user list and dashboard filters, a secret login URL that authenticates as the site's oldest existing administrator, and an unauthenticated file manager accessible via a direct request to the malicious plugin's main PHP file. While the file manager does not support command execution, it could be used to introduce further malicious payloads.
A critical aspect of the attack is its persistence. Even if the "WP Smart Thumbnails" plugin is removed from an infected site, the hidden administrator account and the secret login URL remain functional. This persistence is achieved through separate auxiliary attack plugins, which are designed with backdated timestamps to evade detection. The hidden account is particularly insidious as it does not appear in the standard "Users All Users" list, is not included in the administrator filter, and is not counted in the user totals, yet it maintains full administrative privileges.
Security researchers advise site administrators to immediately update to the latest versions of the affected plugins: Ninja Forms 3.15.4 or later, and WPC Product Bundles for WooCommerce 8.6.7 or later. While updating will prevent future exploitation, it will not remediate existing infections. Therefore, administrators are strongly urged to thoroughly check their sites for any signs of compromise, including the presence of the malicious "WP Smart Thumbnails" plugin, unexpected administrator accounts, or unusual file modifications. Exploitation of these vulnerabilities is currently described as limited, but the potential for widespread impact remains significant given the popularity of the affected plugins.






