Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-10-07 · updated: 2026-10-07 · tags: [cve] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false

Attackers are exploiting stored cross-site scripting in two WordPress plugins — Ninja Forms (CVE-2026-94504, versions ≤3.15.3, active on 500,000+ sites) and WPC Product Bundles for WooCommerce (CVE-2026-93836, versions ≤8.6.6, 30,000+ sites) — to plant backdoors and create rogue admin accounts.

Attribute Detail
CVE CVE-2026-93836
CVSS 7.2 (HIGH)
Vendor / product wpclever — WPC Product Bundles for WooCommerce
Reported 2026-10-07