WordPress plugin stored XSS exploitation campaign targeting WPC Product Bundles for WooCommerce and Ninja Forms
Campaign
Summary
Hide ▲
Show ▼
A WordPress plugin exploitation campaign is using stored XSS in WPC Product Bundles for WooCommerce and Ninja Forms to plant backdoors and create rogue administrator accounts. The same payload was delivered across both plugins, linking the activity to one coordinated operation. The result is persistent administrative control over affected sites and elevated risk of follow-on compromise. Administrators must treat patched systems as potentially already infected if the payload executed.
Related Happenings
WPC Product Bundles for WooCommerce stored XSS actively exploited (CVE-2026-93836)
Vulnerability
H score29
First: 07.10.2026 00:00
Last: 07.10.2026 00:00
Sources 1
How related:
Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
About this happening:
CVE-2026-93836 in WPC Product Bundles for WooCommerce is being actively exploited on WordPress sites, letting attackers plant backdoors and create rogue administ...
WPC Product Bundles for WooCommerce stored XSS actively exploited (CVE-2026-93836)
VulnerabilityHow related: Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
About this happening: CVE-2026-93836 in WPC Product Bundles for WooCommerce is being actively exploited on WordPress sites, letting attackers plant backdoors and create rogue administ...
Ninja Forms stored XSS flaw (CVE-2026-94504)
Vulnerability
H score29
First: 07.10.2026 00:00
Last: 07.10.2026 00:00
Sources 1
How related:
They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
About this happening:
CVE-2026-94504 in Ninja Forms is being exploited on WordPress sites, putting older installs at risk of stored XSS, backdoors, and rogue admin accounts. The...
Ninja Forms stored XSS flaw (CVE-2026-94504)
VulnerabilityHow related: They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
About this happening: CVE-2026-94504 in Ninja Forms is being exploited on WordPress sites, putting older installs at risk of stored XSS, backdoors, and rogue admin accounts. The...
Funnel Builder security patch release (version 3.15.0.3)
Security Patch Release
H score77
First: 16.05.2026 18:20
Last: 16.05.2026 18:20
Sources 1
About this happening:
FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...
Funnel Builder security patch release (version 3.15.0.3)
Security Patch ReleaseAbout this happening: FunnelKit released version 3.15.0.3 to fix a Funnel Builder flaw that was being actively exploited to inject malicious JavaScript into WooCommerce checkout pages...
EssentialPlugin package hit by network compromise
Incident
H score25
First: 15.04.2026 23:33
Last: 15.04.2026 23:33
Sources 1
About this happening:
The EssentialPlugin WordPress package was compromised with a backdoor, enabling unauthorized access to websites running its plugins and putting hundreds of thousands...
EssentialPlugin package hit by network compromise
IncidentAbout this happening: The EssentialPlugin WordPress package was compromised with a backdoor, enabling unauthorized access to websites running its plugins and putting hundreds of thousands...
WordPress.org closes compromised EssentialPlugin plugins with forced update
Security Tool/Service
H score16
First: 15.04.2026 23:33
Last: 15.04.2026 23:33
Sources 1
About this happening:
WordPress.org closed the compromised EssentialPlugin plugins and forced an update, changing how affected sites received and ran the package. The move mattered because the...
WordPress.org closes compromised EssentialPlugin plugins with forced update
Security Tool/ServiceAbout this happening: WordPress.org closed the compromised EssentialPlugin plugins and forced an update, changing how affected sites received and ran the package. The move mattered because the...
Timeline
-
07.10.2026 00:00 1 articles · 1d ago
Stored XSS campaign targets WPC Product Bundles for WooCommerce users
Initial DisclosurePatchstack researchers identified active exploitation against users of WPC Product Bundles for WooCommerce on October 4, with attackers abusing stored XSS to plant backdoors and create rogue administrator accounts. The activity used malicious JavaScript delivered from imgcdn1[.]com and was linked to a larger WordPress plugin compromise campaign.
Show sources
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00
-
07.10.2026 00:00 1 articles · 1d ago
Same JavaScript payload reaches Ninja Forms sites
Campaign Scope UpdateThe next day, the same JavaScript payload from imgcdn1[.]com was observed against Ninja Forms, showing the campaign had expanded beyond WPC Product Bundles for WooCommerce. Researchers said the attacker tries to plant malicious JavaScript in Ninja Forms submissions, which then executes when a logged-in administrator loads the poisoned content.
Show sources
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00
-
07.10.2026 00:00 2 articles · 1d ago
Patchstack urges upgrades for vulnerable WordPress plugins
Mitigation Patch UpdatePatchstack advises upgrading WPC Product Bundles for WooCommerce to version 8.6.7 or later and Ninja Forms to 3.15.4 or later. Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection, so administrators should look for signs of compromise on affected WordPress sites.
Show sources
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00