Ninja Forms flaw exploited to plant WordPress backdoors

Ninja Forms flaw exploited to plant WordPress backdoors

Attackers are abusing stored cross-site scripting (XSS) bugs in two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to create rogue administrator accounts and install backdoors on compromised sites, according to Patchstack.

The two plugins are unrelated, but the attacks against them appear to come from the same source. In both cases, the same JavaScript payload was served from the domain imgcdn1[.]com.

Two plugins, one payload

Ninja Forms lets site owners build custom forms without writing code. It runs on more than 500,000 WordPress sites. WPC Product Bundles for WooCommerce, which groups products into bundles for online shops, is active on more than 30,000 sites.

The flaws are tracked as:

  • CVE-2026-94504, affecting Ninja Forms 3.15.3 and earlier
  • CVE-2026-93836, affecting WPC Product Bundles for WooCommerce 8.6.6 and earlier

Both carry a high severity rating, and both require an authenticated session to exploit.

Patchstack, a security platform focused on WordPress, first spotted the campaign on October 4, when it targeted WPC Product Bundles users. A day later, the same activity showed up against Ninja Forms.

How the attack works

The attacker tries to inject a malicious script, x.js, into WooCommerce order data or Ninja Forms submissions. Nothing happens until a logged-in administrator opens that content. At that point, the script runs inside the admin's authenticated WordPress session.

The script then grabs the administrative nonces it needs and calls legitimate WordPress functions to do two things. It installs a fake plugin called "WP Smart Thumbnails" version 1.2.4, attributed to "MediaPress Labs", and it creates a new administrator account.

From there, the JavaScript payload and the plugin's PHP scripts set up four separate ways back into the site:

  • a visible administrator account
  • an administrator account hidden from the dashboard's user list
  • a secret login URL that signs the visitor in as the site's oldest existing administrator
  • a file manager that requires no authentication and is reached through a direct request to the fake plugin's main PHP file

The file manager can't run commands. It can, however, be used to upload further payloads.

Built to survive cleanup

Removing WP Smart Thumbnails is not enough. The hidden account and the secret login URL keep working through separate helper plugins, which carry backdated timestamps to avoid drawing attention.

Patchstack says the hidden admin is effectively invisible to the site owner. "The [hidden] account does not appear in Users → All Users, does not appear in the Administrator filter, and is not counted in the totals above the list," the researchers explained. "It is a fully privileged administrator the site owner cannot see."

Patches available

Exploitation is limited for now, according to Patchstack. Site owners should update to Ninja Forms 3.15.4 or later and WPC Product Bundles for WooCommerce 8.6.7 or later.

Updating closes the hole, but it does not remove an existing infection. Administrators are strongly advised to look for signs of compromise, including unfamiliar plugins and admin accounts that may not show up in the standard user view.

Why it matters

The campaign shows how a bug that needs authentication can still be dangerous. Here the attacker does not need admin credentials up front. The plan relies on an administrator doing routine work, such as reviewing orders or form entries, and the malicious script borrows that session.

The layered persistence is also worth noting. With four access paths and helper plugins designed to outlive the main backdoor, a quick cleanup is likely to miss something. For site owners, this suggests that recovery should be treated as a full incident response rather than a single plugin removal.

The bigger lesson is a familiar one. As seen in cases where a missed patch led to a major breach, the gap between a fix being released and being applied is where attackers operate, and that window appears to be shrinking as exploitation speeds up. With Ninja Forms installed on more than half a million sites, it is worth watching whether this activity stays limited or spreads now that the technique is public.