type: cve · created: 2026-10-07 · updated: 2026-10-07 · tags: [cve] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false
Attackers are exploiting stored cross-site scripting in two WordPress plugins — Ninja Forms (CVE-2026-94504, versions ≤3.15.3, active on 500,000+ sites) and WPC Product Bundles for WooCommerce (CVE-2026-93836, versions ≤8.6.6, 30,000+ sites) — to plant backdoors and create rogue admin accounts.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-94504 |
| CVSS | 7.2 (HIGH) |
| Vendor / product | Saturday Drive — Ninja Forms |
| Reported | 2026-10-07 |