Vulnerability in Ninja Forms Plugin Used to Compromise WordPress Websites

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Security Vulnerabilities in Popular WordPress Plugins Targeted by Hackers

Recent reports indicate that cybercriminals are capitalizing on stored cross-site scripting (XSS) vulnerabilities found in two distinct WordPress plugins: Ninja Forms and WPC Product Bundles for WooCommerce.

Their objective is to infiltrate these systems to insert backdoors and establish unauthorized administrative accounts.

These vulnerabilities have been assigned a high severity rating, necessitating an authenticated user session for exploitation.

They are cataloged as CVE-2026-93836, impacting WPC Product Bundles for WooCommerce versions 8.6.6 and earlier, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.

The Ninja Forms plugin, a popular tool designed to facilitate custom form creation without coding, boasts installations on over 500,000 websites.

Meanwhile, WPC Product Bundles for WooCommerce enables the bundling of grouped products and is currently utilized on more than 30,000 WordPress sites.

This security threat came to light on October 4, when Patchstack, a prominent WordPress security entity, detected malicious activity targeting users of WPC Product Bundles for WooCommerce. The next day, similar attacks were observed against the Ninja Forms plugin.

In both instances, an identical JavaScript payload was deployed from the domain ‘imgcdn1[.]com’, suggesting the presence of a singular adversarial force orchestrating the attempts on both plugins.

According to the research findings, the perpetrator endeavors to embed a harmful JavaScript file (known as x.js) within either WooCommerce order details or Ninja Forms submissions.

The execution of this script occurs when a logged-in administrator accesses the compromised content, utilizing the active WordPress session.

Upon activation, the script retrieves essential administrative nonces and employs legitimate WordPress functions to deploy a malicious plugin that masquerades as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs,” subsequently creating an administrator account.

At this juncture, both the JavaScript payload and the compromised plugin’s PHP scripts establish four distinct access pathways to the infiltrated site:

  1. A visible administrator account.
  2. An administrator account that remains hidden from the WordPress user list in the dashboard.
  3. A clandestine login URL that authenticates using the site’s oldest existing administrator credentials.
  4. An unauthenticated file manager accessible through a straight request to the main PHP file of the malicious plugin

While the file manager lacks the capability to execute commands, it remains susceptible to introducing additional harmful payloads onto the site.

Even after the removal of the WP Smart Thumbnails plugin from the compromised site, the hidden administrator account and secret login URL persist as mechanisms for maintaining access.

This is facilitated through auxiliary attack plugins with backdated timestamps that are designed to evade detection.

“The [hidden] account does not appear in Users → All Users, does not appear in the Administrator filter, and is not counted in the totals above the list,” Patchstack elucidates, further commenting, “It is a fully privileged administrator the site owner cannot see.”

While the exploitation is currently deemed to be limited, Patchstack advises website administrators to upgrade to the most recent versions of the affected plugins: WPC Product Bundles for WooCommerce version 8.6.7 or newer and Ninja Forms 3.15.4 or newer.

A white 3D square button with a purple Woo speech bubble logo, floating above a purple background.

Updating these vulnerable plugins mitigates the risk of further exploitation; however, it does not rectify an existing infection. Administrators are strongly urged to scrutinize their sites for any signs of compromise.

Source link: Bleepingcomputer.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading