ConicPlex

Start Your Project

A laptop and monitor glow with blue light on a dark desk next to an ID badge and a hidden second keycard tucked under papers

On this Page

Ninja Forms and WooCommerce Plugin Flaws Are Being Exploited to Hide Admin Backdoors

Aftab Memon

October 8, 2026

Patchstack and BleepingComputer are tracking an active campaign that chains stored cross-site scripting flaws in two popular WordPress plugins, WPC Product Bundles for WooCommerce and Ninja Forms, to plant hidden administrator accounts on compromised sites. Patchstack first observed exploitation against WPC Product Bundles on October 4, 2026, and against Ninja Forms a day later. WPC Product Bundles for WooCommerce runs on more than 30,000 sites, Ninja Forms on more than 500,000, and patches already exist for both: version 8.6.7 for WPC Product Bundles and 3.15.4 for Ninja Forms.

What the Ninja Forms and WooCommerce Vulnerabilities Actually Do

The WooCommerce side is tracked as CVE-2026-93836, rated 7.1 on the CVSS scale. It lives in the quantity field WPC Product Bundles writes into WooCommerce order metadata. An attacker sends a crafted value through the plugin’s woosb_ids parameter, a number that looks valid followed by a <script> tag. The order metadata stores that value as-is, and it runs the moment a store admin opens the order in wp-admin.

The Ninja Forms side is CVE-2026-94504, also rated 7.1. Non-rich-text textarea submissions get rendered without proper escaping in the plugin’s legacy admin submission editor. An attacker submits a form response through the normal nf_ajax_submit AJAX action, closing the textarea early and adding an img tag with an onerror handler. The handler fires the same payload the instant an administrator opens that submission.

Affected versions are WPC Product Bundles for WooCommerce 8.6.6 and earlier, and Ninja Forms 3.15.3 and earlier. If you’re already on 8.6.7 or 3.15.4, you’re patched against new exploitation, though that alone doesn’t tell you whether an older version on your site was already hit.

Why This Isn’t a Typical Stored XSS

Both payloads load the same external script from a domain Patchstack identifies as imgcdn1[.]com, which is how the two separate advisories got tied to one actor. Once that script runs inside an administrator’s authenticated session, it pulls the nonces it needs and uses WordPress’s own plugin uploader, legitimately, to install a fake plugin billed as “WP Smart Thumbnails” from a made-up vendor called “MediaPress Labs.”

From there it sets up four separate ways back in: a visible new admin account, a second admin account hidden from the Users screen by a must-use plugin, a secret login URL that authenticates as whatever admin account on the site is oldest, and an unauthenticated file manager that can read and write files. Deleting the fake plugin removes none of the other three. The hidden account, the login URL, and the file manager all live in separate files the attacker backdates so they blend into the rest of the install.

What to Do if You Run Either Plugin

  • Update WPC Product Bundles for WooCommerce to 8.6.7 or later, and Ninja Forms to 3.15.4 or later, right away. The patch stops new exploitation but won’t clean an infection that already landed.
  • Check your wp_users table directly for administrator accounts, rather than trusting what the Users screen in wp-admin shows you.
  • Search wp-content/mu-plugins for anything you don’t recognize, especially files with timestamps that look older than they should.
  • Look through your installed plugins for one called “WP Smart Thumbnails.” It isn’t a real product. Remove it if present, then rotate every administrator password and any API keys stored in the database.

If you’re running a WooCommerce store on plugins nobody’s audited in a while, this is exactly the kind of exposure a WooCommerce Development review is built to catch: data that gets stored and rendered without escaping, long before it turns into an admin account you never created.

The four-backdoor pattern here isn’t new on its own. It’s close to what a supply chain attack on Elementor add-ons did to create rogue admins earlier this year, and it shares the same instinct for hiding in places a cleanup script won’t check as a backdoor covered here in October that survives cleanup by hiding in files, database, and memory. The plugins change. The playbook for staying in after the obvious fix gets applied doesn’t.

Sources

Aftab Memon is a Senior WordPress Developer at ConicPlex, working across everything from plugin conflicts and theme customization to full site builds on Elementor and WooCommerce. He spends most of his time in the parts of WordPress that don’t show up in a features list: hosting quirks, hook priority, the difference between a plugin that works in isolation and one that survives a real production stack. He writes here about what actually holds up once a WordPress site is live and being run by a non-technical client, not just what works in a demo.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Plugins

Flat illustration of a price tag with a phone handset icon in place of the price, representing WooCommerce Call for Price plugins

How to Show Call for Price Instead of Add to Cart in WooCommerce (4 Plugins Compared)

If you run a wholesale, B2B, or made-to-order WooCommerce store, a fixed price field does not always make sense. This…

Sajil Memon

October 8, 2026

Guides

An empty clinic reception desk at night with a tablet on the counter displaying a glowing blue chat interface next to a privacy screen

How to Build a HIPAA-Compliant AI Chatbot for a Healthcare Website

What actually makes an AI chatbot HIPAA compliant: a signed BAA, encryption, patient verification, and audit logging, plus when a…

Husen Memon

October 7, 2026

News & Updates, Plugins

A darkened appointment-business reception desk at night with a monitor showing an abstract blue booking calendar grid, a brass keycard resting near the keyboard, and a phone face-down on the desk.

LatePoint Patches a Critical Unauthenticated Shortcode Injection Flaw (CVE-2026-92966)

LatePoint, a WordPress appointment booking plugin running on more than 100,000 service-business sites, has patched a critical vulnerability that let…

Aftab Memon

October 7, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant