Patchstack and BleepingComputer are tracking an active campaign that chains stored cross-site scripting flaws in two popular WordPress plugins, WPC Product Bundles for WooCommerce and Ninja Forms, to plant hidden administrator accounts on compromised sites. Patchstack first observed exploitation against WPC Product Bundles on October 4, 2026, and against Ninja Forms a day later. WPC Product Bundles for WooCommerce runs on more than 30,000 sites, Ninja Forms on more than 500,000, and patches already exist for both: version 8.6.7 for WPC Product Bundles and 3.15.4 for Ninja Forms.
What the Ninja Forms and WooCommerce Vulnerabilities Actually Do
The WooCommerce side is tracked as CVE-2026-93836, rated 7.1 on the CVSS scale. It lives in the quantity field WPC Product Bundles writes into WooCommerce order metadata. An attacker sends a crafted value through the plugin’s woosb_ids parameter, a number that looks valid followed by a <script> tag. The order metadata stores that value as-is, and it runs the moment a store admin opens the order in wp-admin.
The Ninja Forms side is CVE-2026-94504, also rated 7.1. Non-rich-text textarea submissions get rendered without proper escaping in the plugin’s legacy admin submission editor. An attacker submits a form response through the normal nf_ajax_submit AJAX action, closing the textarea early and adding an img tag with an onerror handler. The handler fires the same payload the instant an administrator opens that submission.
Affected versions are WPC Product Bundles for WooCommerce 8.6.6 and earlier, and Ninja Forms 3.15.3 and earlier. If you’re already on 8.6.7 or 3.15.4, you’re patched against new exploitation, though that alone doesn’t tell you whether an older version on your site was already hit.
Why This Isn’t a Typical Stored XSS
Both payloads load the same external script from a domain Patchstack identifies as imgcdn1[.]com, which is how the two separate advisories got tied to one actor. Once that script runs inside an administrator’s authenticated session, it pulls the nonces it needs and uses WordPress’s own plugin uploader, legitimately, to install a fake plugin billed as “WP Smart Thumbnails” from a made-up vendor called “MediaPress Labs.”
From there it sets up four separate ways back in: a visible new admin account, a second admin account hidden from the Users screen by a must-use plugin, a secret login URL that authenticates as whatever admin account on the site is oldest, and an unauthenticated file manager that can read and write files. Deleting the fake plugin removes none of the other three. The hidden account, the login URL, and the file manager all live in separate files the attacker backdates so they blend into the rest of the install.
What to Do if You Run Either Plugin
- Update WPC Product Bundles for WooCommerce to 8.6.7 or later, and Ninja Forms to 3.15.4 or later, right away. The patch stops new exploitation but won’t clean an infection that already landed.
- Check your
wp_userstable directly for administrator accounts, rather than trusting what the Users screen in wp-admin shows you. - Search
wp-content/mu-pluginsfor anything you don’t recognize, especially files with timestamps that look older than they should. - Look through your installed plugins for one called “WP Smart Thumbnails.” It isn’t a real product. Remove it if present, then rotate every administrator password and any API keys stored in the database.
If you’re running a WooCommerce store on plugins nobody’s audited in a while, this is exactly the kind of exposure a WooCommerce Development review is built to catch: data that gets stored and rendered without escaping, long before it turns into an admin account you never created.
The four-backdoor pattern here isn’t new on its own. It’s close to what a supply chain attack on Elementor add-ons did to create rogue admins earlier this year, and it shares the same instinct for hiding in places a cleanup script won’t check as a backdoor covered here in October that survives cleanup by hiding in files, database, and memory. The plugins change. The playbook for staying in after the obvious fix gets applied doesn’t.



