Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-07 · updated: 2026-10-07 · tags: [incident, retail] · confidence: medium · severity: high · affected_sectors: [retail] · au_impact: true

Attackers are exploiting stored cross-site scripting in two WordPress plugins — Ninja Forms (CVE-2026-94504, versions ≤3.15.3, active on 500,000+ sites) and WPC Product Bundles for WooCommerce (CVE-2026-93836, versions ≤8.6.6, 30,000+ sites) — to plant backdoors and create rogue admin accounts. WordPress-security vendor Patchstack identified the campaign against WPC on 4 October and against Ninja Forms the next day; both deliver the same JavaScript payload from imgcdn1[.]com, indicating a single threat actor. The script fires when a logged-in administrator loads content, then uses legitimate WordPress functions to install a malicious plugin ("WP Smart Thumbnails" from a spoofed vendor) and create admin accounts — including one hidden from the user list, a secret login URL authenticating as the oldest admin, and an unauthenticated file manager. Even after removing the plugin, the hidden account and login persist. Exploitation is currently limited; admins must patch and check for compromise.

Attribute Detail
Sector Retail & Entertainment & Sport
Date 2026-10-07
Source BleepingComputer
Reliability Tier 2
CVEs CVE-2026-93836, CVE-2026-94504