Skip to main content

Ninja Forms and WPC Product Bundles Flaws Being Used to Plant Backdoors on WordPress Sites (CVE-2026-94504 / CVE-2026-93836)

Scope: Ninja Forms WordPress plugin versions 3.15.3 and earlier, and WPC Product Bundles for WooCommerce versions 8.6.6 and earlier

Severity: Amber

Two unrelated plugins, Ninja Forms and WPC Product Bundles for WooCommerce, are both being targeted in the same campaign, each through its own stored cross-site scripting flaw. The attacker hides a malicious script inside a Ninja Forms submission or a WooCommerce order, and when a logged-in administrator views that content from the WordPress dashboard, the script runs with the admin's own session. From there it plants a hidden admin account and a secret login URL, and according to Patchstack the attackers have also built in separate auxiliary plugins with backdated file timestamps specifically to make the persistence harder to spot during a cleanup. Both flaws need an authenticated session to trigger, which keeps the bar higher than a fully unauthenticated bug, but exploitation is already happening, just at a limited scale so far. Updating closes the door to new attacks but does nothing for a site that is already compromised. Administrators must update Ninja Forms to 3.15.4 or later and WPC Product Bundles to 8.6.7 or later, and separately check the WordPress user list for any administrator account that should not be there.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.