Ninja Forms plugin flaw exploited to hack WordPress sites

A critical vulnerability in the Ninja Forms plugin for WordPress has been exploited by hackers, compromising thousands of websites. The attack also affects users of WPC Product Bundles for WooCommerce, another popular plugin with over 30,000 installations.

The exploit takes advantage of a stored cross-site scripting (XSS) flaw, which requires an authenticated session to launch. This means that only administrators or users who have logged in can be targeted by the attackers. The vulnerability is rated high severity and has been assigned two separate Common Vulnerabilities and Exposures (CVE) numbers: CVE-2026-93836 for WPC Product Bundles for WooCommerce and CVE-2026-94504 for Ninja Forms.

Ninja Forms, a plugin that allows users to create custom forms without writing code, is installed on over 500,000 WordPress sites. Its popularity makes it an attractive target for hackers, who can use the exploit to install backdoors and create rogue administrator accounts. The same JavaScript payload is being delivered from ‘imgcdn1[.]com’, indicating a single threat actor behind both attacks.

When an attacker plants malicious JavaScript code in WooCommerce order data or Ninja Forms submissions, it executes using the authenticated WordPress session. This allows the script to retrieve administrative nonces and use legitimate WordPress functions to install a malicious plugin masquerading as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs”. The plugin creates four access mechanisms to the compromised site: a visible administrator account, an administrator account concealed from the WordPress user list in the dashboard, a secret login URL that authenticates as the site’s oldest existing administrator, and an unauthenticated file manager accessible through a direct request.

Even if the malicious WP Smart Thumbnails plugin is removed from the infected website, the hidden account and secret login URL continue to function as persistence mechanisms. This makes it essential for administrators to remove any auxiliary attack plugins featuring backdated timestamps to evade detection.

Patchstack, a WordPress security platform, has identified the campaign and advises site admins to upgrade to the latest versions of the affected plugins: WPC Product Bundles for WooCommerce version 8.6.7 or later and Ninja Forms 3.15.4 or later. While updating the vulnerable plugin prevents further exploitation, it does not clean an existing infection. Administrators are strongly recommended to check for signs of compromise.

To protect your WordPress site from this type of attack, ensure you’re running the latest versions of all installed plugins and themes. Regularly scan your website for malware and monitor your security logs for any suspicious activity. Additionally, consider implementing a web application firewall (WAF) to block potential threats and limit the damage caused by an exploit. By staying up-to-date with the latest security patches and taking proactive measures, you can significantly reduce the risk of falling victim to this type of attack.


Source: Bleeping Computer — 2026-10-06