Ninja Forms stored XSS flaw (CVE-2026-94504)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-94504 in Ninja Forms is being exploited on WordPress sites, putting older installs at risk of stored XSS, backdoors, and rogue admin accounts. The flaw affects versions 3.15.3 and older and requires an authenticated session to exploit. Attackers can inject JavaScript into form submissions, which runs when a logged-in administrator opens the content. Administrators are advised to upgrade to Ninja Forms 3.15.4 or later.
Related Happenings
WordPress plugin stored XSS exploitation campaign targeting WPC Product Bundles for WooCommerce and Ninja Forms
Campaign
H score29
First: 07.10.2026 00:00
Last: 07.10.2026 00:00
Sources 1
How related:
The campaign was identified on October 4 by researchers at WordPress security platform Patchstack, against users of WPC Product Bundles for WooCommerce.
About this happening:
A WordPress plugin exploitation campaign is using stored XSS in WPC Product Bundles for WooCommerce and Ninja Forms to plant backdoors and create rogue admin...
WordPress plugin stored XSS exploitation campaign targeting WPC Product Bundles for WooCommerce and Ninja Forms
CampaignHow related: The campaign was identified on October 4 by researchers at WordPress security platform Patchstack, against users of WPC Product Bundles for WooCommerce.
About this happening: A WordPress plugin exploitation campaign is using stored XSS in WPC Product Bundles for WooCommerce and Ninja Forms to plant backdoors and create rogue admin...
WPC Product Bundles for WooCommerce stored XSS actively exploited (CVE-2026-93836)
Vulnerability
H score29
First: 07.10.2026 00:00
Last: 07.10.2026 00:00
Sources 1
How related:
Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
About this happening:
CVE-2026-93836 in WPC Product Bundles for WooCommerce is being actively exploited on WordPress sites, letting attackers plant backdoors and create rogue administ...
WPC Product Bundles for WooCommerce stored XSS actively exploited (CVE-2026-93836)
VulnerabilityHow related: Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
About this happening: CVE-2026-93836 in WPC Product Bundles for WooCommerce is being actively exploited on WordPress sites, letting attackers plant backdoors and create rogue administ...
CISA KEV multi-product active exploitation wave (CVE-2020-7796)
Exploitation Wave
H score53
First: 18.02.2026 08:52
Last: 18.02.2026 08:52
Sources 1
About this happening:
CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...
CISA KEV multi-product active exploitation wave (CVE-2020-7796)
Exploitation WaveAbout this happening: CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...
Timeline
-
07.10.2026 00:00 2 articles · 3h ago
Attackers use Ninja Forms stored XSS to plant malicious JavaScript on WordPress sites
Exploitation ObservedAttackers used stored XSS in the WordPress plugin Ninja Forms on vulnerable sites to plant malicious JavaScript in form submissions, where it executed when a logged-in administrator loaded the content and could retrieve administrative nonces, install a malicious plugin masquerading as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs,” and create administrator access for persistence.
Show sources
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00