Hackers Exploit Ninja Forms and WooCommerce Plugin Flaws to Create Hidden Admin Accounts
Hackers are actively exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins—Ninja Forms and WPC Product Bundles for WooCommerce—to install backdoors and create fraudulent administrator accounts.
Both vulnerabilities have high severity scores and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and later, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and later.
More than 500,000 WordPress sites use Ninja Forms
Ninja Forms is a WordPress plugin that allows users to create custom forms without writing code. It is installed on more than 500,000 websites.
WPC Product Bundles for WooCommerce lets store owners group products into bundles and is active on more than 30,000 WordPress sites.
Same malware campaign targets both plugins
The campaign was identified on October 4 by researchers at WordPress security platform Patchstack while investigating attacks against users of WPC Product Bundles for WooCommerce. The same activity was observed targeting Ninja Forms the following day.
Both attacks delivered the same JavaScript payload from imgcdn1[.]com, indicating that the same threat actor is likely behind the exploitation attempts against both plugins.
According to Patchstack, attackers used a malicious JavaScript file named x.js to target WooCommerce order data or Ninja Forms content. When a logged-in administrator loads the malicious content, the script executes within an authenticated WordPress session.
Attackers install a fake plugin and create administrator accounts
After execution, the payload obtains the required administrative nonce and abuses legitimate WordPress functionality to install a malicious plugin disguised as WP Smart Thumbnails version 1.2.4 from MediaPress Labs. It also creates a new administrator account.
The JavaScript payload and malicious PHP plugin establish four separate ways to maintain access to the compromised website:
- A visible administrator account
- An administrator account hidden from the WordPress user list in the dashboard
- A secret login URL that authenticates attackers as the site’s oldest existing administrator
- An unauthenticated file manager accessible through a direct request to the malicious plugin’s main PHP file
Although the file manager cannot execute commands, attackers can use it to upload additional payloads to the website.
Removing the fake plugin may not remove the infection
Even after the WP Smart Thumbnails plugin is removed, the hidden administrator account and secret login URL can continue providing access. They are supported by a separate auxiliary attack plugin with timestamps set in the past to evade detection.
“The [hidden] account does not appear in Users → All Users, does not appear in the admin filter, and does not count in the total above the list.”
Patchstack added: “This is a fully privileged administrator and is invisible to the site owner.”
Read Patchstack’s full analysis of the WordPress XSS campaign.
WordPress administrators should update immediately
Patchstack says exploitation is limited at this time but advises administrators to upgrade to the latest versions of the affected plugins:
- WPC Product Bundles for WooCommerce: version 8.6.7 or later
- Ninja Forms: version 3.15.4 or later
Updating the vulnerable plugins will prevent further exploitation, but it will not remove existing infections. Administrators are strongly encouraged to check their websites for signs of compromise, including unauthorized administrator accounts, suspicious plugins, hidden login mechanisms and unfamiliar files.
Join Mikko Hypponen and security leaders from the NFL, Chanel and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix and revalidate at machine speed.
Source: www.bleepingcomputer.com



