As reported by BleepingComputer, a threat actor is actively exploiting stored cross-site scripting (XSS) vulnerabilities in two widely deployed WordPress plugins — Ninja Forms and WPC Product Bundles for WooCommerce — to compromise sites through a multi-stage payload delivery chain. This is not a theoretical risk; exploitation is underway, and the persistence mechanisms deployed are sophisticated enough to survive naive remediation.
Vulnerability Summary
| CVE | Plugin | Affected Versions | Severity | Exploited in the Wild |
|---|---|---|---|---|
| CVE-2026-94504 | Ninja Forms | ≤ 3.15.3 | High | Yes — observed October 5, 2026 |
| CVE-2026-93836 | WPC Product Bundles for WooCommerce | ≤ 8.6.6 | High | Yes — observed October 4, 2026 |
Ninja Forms is installed on over 500,000 WordPress sites, making CVE-2026-94504 the more consequential of the two given its sheer exposure surface. Both flaws are authenticated stored XSS, meaning the attacker must have some level of session validity — but in WordPress ecosystems, subscriber-level accounts, customer accounts from WooCommerce purchases, or any form-submitting user can serve as the entry point. This significantly broadens the attacker surface beyond what many administrators assume.
Why This Campaign Stands Out
The attack chain described demonstrates a level of operational maturity that goes beyond opportunistic defacement or redirect injections. The threat actor is weaponizing stored XSS to hijack authenticated admin sessions, then leveraging WordPress's own legitimate nonce system and plugin installation APIs to deploy a malicious plugin disguised as "WP Smart Thumbnails" version 1.2.4 from a fictitious "MediaPress Labs". This abuse of native WordPress functionality means traditional detection tools that look for known malware signatures or suspicious file writes may miss the activity entirely — from WordPress's perspective, a logged-in admin is performing expected actions.
The persistence layer is particularly insidious: even after removing the malicious plugin, hidden administrator accounts and secret login URLs continue to function through auxiliary plugins with backdated timestamps designed to evade forensic review.
This means that simply deleting the fake plugin is insufficient. Site operators who discover compromise and only remove the visible components will likely retain active backdoor access for the attacker, hidden from the WordPress admin dashboard's user list entirely.
Who Is Most at Risk
Shield53 Recommendations
Immediate Actions
- Patch both plugins now. Update Ninja Forms to a version newer than 3.15.3 and WPC Product Bundles to a version newer than 8.6.6. Verify the update completed successfully.
- Audit wp_users table directly via database query — do not rely on the WordPress admin UI user list, as hidden admin accounts are deliberately concealed from it. Query
SELECT ID, user_login, user_email, user_registered FROM wp_users;and cross-reference every account against known legitimate administrators. - Search for the fake plugin by scanning
wp-content/plugins/for any directory named or referencing "wp-smart-thumbnails" or "WP Smart Thumbnails." Also check for any plugin with an unusually old or backdated timestamp relative to its actual install date. - Review installed plugins list for any plugin claiming to be from "MediaPress Labs" — this is not a legitimate vendor.
- Block the known IOC
imgcdn1[.]comat your WAF, DNS resolver, or .htaccess level to disrupt active payload delivery. - Rotate WordPress salts and keys in
wp-config.phpafter cleaning compromise — this invalidates all existing session tokens and nonces, neutralizing any stolen session data. - Force password resets for all administrator-level accounts.
Detection & Hardening
- Review web server access logs for POST requests to
/wp-admin/admin-ajax.phporiginating from sessions that subsequently accessedplugin-install.phporupdate.phpwith unexpected plugin slugs - Implement Content Security Policy (CSP) headers with restrictive
script-srcdirectives to mitigate stored XSS execution even before patching - Disable file editing in
wp-config.phpviadefine('DISALLOW_FILE_EDIT', true);and considerDISALLOW_FILE_MODSif plugin installation via admin UI is not required - Restrict WordPress admin access by IP allowlisting where feasible
- Deploy a Web Application Firewall with WordPress-specific rule sets that inspect form submission payloads for XSS injection patterns
The convergence of two unrelated plugins being exploited by the same actor with identical infrastructure suggests a systematic scanning campaign targeting the WordPress plugin ecosystem. Given that Ninja Forms alone covers half a million sites, we expect exploitation attempts to intensify before patches are broadly applied. Site owners should treat this as an active incident requiring immediate response — not a routine update to schedule for the next maintenance window.