LIVE · cybersecurity feed
Live wire
ASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE Publication
CVE-2026-93836high

Ninja Forms plugin flaw exploited to hack WordPress sites

Cybersecurity researchers have identified an active exploitation campaign targeting two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, leveraging stored cross-site scripting (XSS) vulnerabilities to compromise websites. The attacks, first observed on October 4 against WPC Product Bundles for WooCommerce users and then on October 5 against Ninja Forms users, involve the…

ZeroDay News ·

Source: BleepingComputer

Cybersecurity researchers have identified an active exploitation campaign targeting two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, leveraging stored cross-site scripting (XSS) vulnerabilities to compromise websites. The attacks, first observed on October 4 against WPC Product Bundles for WooCommerce users and then on October 5 against Ninja Forms users, involve the delivery of a consistent JavaScript payload from the domain imgcdn1[.]com, suggesting a single threat actor is behind both efforts.

The vulnerabilities, tracked as CVE-2026-94504 for Ninja Forms versions 3.15.3 and older, and CVE-2026-93836 for WPC Product Bundles for WooCommerce versions 8.6.6 and older, both carry a high severity rating and require an authenticated session for exploitation. Ninja Forms is a popular plugin used on over 500,000 WordPress sites for creating custom forms, while WPC Product Bundles for WooCommerce, active on more than 30,000 sites, facilitates grouping products into bundles.

The attack chain begins with the threat actor injecting malicious JavaScript, specifically a file named `x.js`, into WooCommerce order data or Ninja Forms submissions. When a logged-in administrator views this content, the script executes within their authenticated WordPress session. It then retrieves necessary administrative nonces and utilizes legitimate WordPress functions to install a malicious plugin, disguised as "WP Smart Thumbnails version 1.2.4 from MediaPress Labs," and simultaneously creates a new administrator account.

This process establishes four distinct access mechanisms to the compromised site. These include a visible administrator account, an administrator account that is hidden from the WordPress user list and dashboard filters, a secret login URL that authenticates as the site's oldest existing administrator, and an unauthenticated file manager accessible via a direct request to the malicious plugin's main PHP file. While the file manager does not support command execution, it could be used to introduce further malicious payloads.

A critical aspect of the attack is its persistence. Even if the "WP Smart Thumbnails" plugin is removed from an infected site, the hidden administrator account and the secret login URL remain functional. This persistence is achieved through separate auxiliary attack plugins, which are designed with backdated timestamps to evade detection. The hidden account is particularly insidious as it does not appear in the standard "Users All Users" list, is not included in the administrator filter, and is not counted in the user totals, yet it maintains full administrative privileges.

Security researchers advise site administrators to immediately update to the latest versions of the affected plugins: Ninja Forms 3.15.4 or later, and WPC Product Bundles for WooCommerce 8.6.7 or later. While updating will prevent future exploitation, it will not remediate existing infections. Therefore, administrators are strongly urged to thoroughly check their sites for any signs of compromise, including the presence of the malicious "WP Smart Thumbnails" plugin, unexpected administrator accounts, or unusual file modifications. Exploitation of these vulnerabilities is currently described as limited, but the potential for widespread impact remains significant given the popularity of the affected plugins.

vulnerabilities in this storyCVE-2026-93836CVE-2026-94504
wordpressxssvulnerabilitypluginbackdoor
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Anthropic reconfigures its cool kids security program

Anthropic has announced a restructuring of its cybersecurity initiatives, merging its Project Glasswing and Cyber Verification Program (CVP) into a single, tiered offering. This change, effective as of October 2026, aims to provide more security organizations with access to Anthropic's AI capabilities for system protection.

data breachhigh

ASOS Hackers Hijack App Notifications, Claim Snowflake Data Breach

ASOS is currently investigating a cybersecurity incident where unauthorized actors leveraged the company's official mobile application to disseminate threatening notifications to its customer base. The messages, sent directly through the app's notification system, asserted that the attackers had successfully breached Snowflake and subsequently gained access to ASOS customer data.

ai securityhigh

Karina Portugal Makes the Case for Know Your Agent

Karina Portugal, a Director at Prove Identity, has reportedly advocated for a new security paradigm termed "Know Your Agent" (KYA). This concept addresses the emerging challenges in verifying autonomous software agents, which traditional "Know Your Customer" (KYC) methodologies are not equipped to handle. The core argument is that existing KYC frameworks primarily focus on human user identity,…

fortinethigh

Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks

The FBI and Secret Service have issued a joint alert regarding "FortiBleed," a credential compromise campaign targeting Fortinet firewalls and VPN gateways. The agencies confirm that the campaign remains active and poses a significant threat, potentially leading to user lockouts and serving as an initial entry point for ransomware attacks.

clickfix

ClickFix Attacks Evolve to Better Hide Malicious Payloads

Recent reports indicate a significant evolution in ClickFix attack methodologies, with cybercriminals now employing more sophisticated techniques to mask their malicious payloads. The updated tactics reportedly involve the use of DNS TXT records and browser cache pre-fetching, strategies designed to make the early detection of these threats considerably more difficult for security systems and…

patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…