Hackers have been exploiting a severe vulnerability in two popular WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to gain unauthorized access to thousands of websites. The attacks, which were identified by security researchers at Patchstack, involve installing backdoors and creating hidden administrator accounts that can’t be detected or removed.
The vulnerability affects multiple sites, with over 500,000 WordPress installations using Ninja Forms and more than 30,000 using WPC Product Bundles for WooCommerce. These plugins allow website owners to create custom forms and bundle products together, respectively. The hackers are targeting users of both plugins by exploiting a stored cross-site scripting (XSS) flaw that allows them to inject malicious JavaScript code into the websites.
The JavaScript payload is planted in WooCommerce order data or Ninja Forms submissions, and when an administrator loads the content, it executes using their authenticated WordPress session. This allows the attackers to install a fake plugin called “WP Smart Thumbnails” and create multiple administrator accounts, including some that are hidden from view.
One of these accounts is particularly sneaky: it’s a fully privileged administrator account that doesn’t appear in the WordPress user list or in the Administrator filter, making it invisible to site owners. This hidden account can still access and control the website, even if the fake plugin is removed.
The attacks are limited so far, but Patchstack advises all users of these plugins to upgrade to the latest versions immediately: WPC Product Bundles for WooCommerce version 8.6.7 or later, and Ninja Forms 3.15.4 or later. Updating the vulnerable plugin will prevent further exploitation, but it won’t remove any existing infections – site admins should also check their websites for signs of compromise.
The fact that these attacks involve a single JavaScript payload delivered from a specific domain, ‘imgcdn1[.]com’, suggests that the same threat actor is behind both exploits. This highlights the importance of staying vigilant and keeping software up-to-date in today’s cybersecurity landscape. By taking proactive steps to secure their websites, site owners can prevent similar attacks from succeeding in the future.
In light of this incident, we recommend that all WordPress users review their plugin usage and ensure they’re running the latest versions. Regularly monitoring your website for suspicious activity is also crucial – keep an eye out for any hidden administrator accounts or unexpected changes to your website’s functionality.
Source: Bleeping Computer — 2026-10-06