Attackers are exploiting stored cross-site scripting in two WordPress plugins — Ninja Forms (CVE-2026-94504, versions ≤3.15.3, active on 500,000+ sites) and WPC Product Bundles for WooCommerce (CVE-2026-93836, versions ≤8.6.6, 30,000+ sites) — to plant backdoors and create rogue admin accounts. WordPress-security vendor Patchstack identified the campaign against WPC on 4 October and against Ninja Forms the next day; both deliver the same JavaScript payload from imgcdn1[.]com, indicating a single threat actor. The script fires when a logged-in administrator loads content, then uses legitimate WordPress functions to install a malicious plugin ("WP Smart Thumbnails" from a spoofed vendor) and create admin accounts — including one hidden from the user list, a secret login URL authenticating as the oldest admin, and an unauthenticated file manager. Even after removing the plugin, the hidden account and login persist. Exploitation is currently limited; admins must patch and check for compromise.
| Attribute | Detail |
|---|---|
| Sector | Retail & Entertainment & Sport |
| Date | 2026-10-07 |
| Source | BleepingComputer |
| Reliability | Tier 2 |
| CVEs | CVE-2026-93836, CVE-2026-94504 |