Find notable cyber news and cases, enriched with sources, timelines, and signals.

WordPress plugin stored XSS exploitation campaign targeting WPC Product Bundles for WooCommerce and Ninja Forms

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

A WordPress plugin exploitation campaign is using stored XSS in WPC Product Bundles for WooCommerce and Ninja Forms to plant backdoors and create rogue administrator accounts. The same payload was delivered across both plugins, linking the activity to one coordinated operation. The result is persistent administrative control over affected sites and elevated risk of follow-on compromise. Administrators must treat patched systems as potentially already infected if the payload executed.

Related Happenings

WPC Product Bundles for WooCommerce stored XSS actively exploited (CVE-2026-93836)

Vulnerability
H score29 First: 07.10.2026 00:00 Last: 07.10.2026 00:00 Sources 1

How related: Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.

About this happening: CVE-2026-93836 in WPC Product Bundles for WooCommerce is being actively exploited on WordPress sites, letting attackers plant backdoors and create rogue administ...

Ninja Forms stored XSS flaw (CVE-2026-94504)

Vulnerability
H score29 First: 07.10.2026 00:00 Last: 07.10.2026 00:00 Sources 1

How related: They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.

About this happening: CVE-2026-94504 in Ninja Forms is being exploited on WordPress sites, putting older installs at risk of stored XSS, backdoors, and rogue admin accounts. The...

Funnel Builder security patch release (version 3.15.0.3)

Security Patch Release
H score77 First: 16.05.2026 18:20 Last: 16.05.2026 18:20 Sources 1

About this happening: FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...

EssentialPlugin package hit by network compromise

Incident
H score25 First: 15.04.2026 23:33 Last: 15.04.2026 23:33 Sources 1

About this happening: The EssentialPlugin WordPress package was compromised with a backdoor, enabling unauthorized access to websites running its plugins and putting hundreds of thousands...

WordPress.org closes compromised EssentialPlugin plugins with forced update

Security Tool/Service
H score16 First: 15.04.2026 23:33 Last: 15.04.2026 23:33 Sources 1

About this happening: WordPress.org closed the compromised EssentialPlugin plugins and forced an update, changing how affected sites received and ran the package. The move mattered because the...

Timeline

  1. 07.10.2026 00:00 1 articles · 1d ago

    Stored XSS campaign targets WPC Product Bundles for WooCommerce users

    Initial Disclosure

    Patchstack researchers identified active exploitation against users of WPC Product Bundles for WooCommerce on October 4, with attackers abusing stored XSS to plant backdoors and create rogue administrator accounts. The activity used malicious JavaScript delivered from imgcdn1[.]com and was linked to a larger WordPress plugin compromise campaign.

    Show sources
  2. 07.10.2026 00:00 1 articles · 1d ago

    Same JavaScript payload reaches Ninja Forms sites

    Campaign Scope Update

    The next day, the same JavaScript payload from imgcdn1[.]com was observed against Ninja Forms, showing the campaign had expanded beyond WPC Product Bundles for WooCommerce. Researchers said the attacker tries to plant malicious JavaScript in Ninja Forms submissions, which then executes when a logged-in administrator loads the poisoned content.

    Show sources
  3. 07.10.2026 00:00 2 articles · 1d ago

    Patchstack urges upgrades for vulnerable WordPress plugins

    Mitigation Patch Update

    Patchstack advises upgrading WPC Product Bundles for WooCommerce to version 8.6.7 or later and Ninja Forms to 3.15.4 or later. Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection, so administrators should look for signs of compromise on affected WordPress sites.

    Show sources