WPC Product Bundles for WooCommerce stored XSS actively exploited (CVE-2026-93836)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-93836 in WPC Product Bundles for WooCommerce is being actively exploited on WordPress sites, letting attackers plant backdoors and create rogue administrator accounts. The flaw affects version 8.6.6 and older and requires an authenticated session. Patchstack identified the activity on October 4, 2026, with exploitation continuing into October 5.
Related Happenings
WordPress plugin stored XSS exploitation campaign targeting WPC Product Bundles for WooCommerce and Ninja Forms
Campaign
H score29
First: 07.10.2026 00:00
Last: 07.10.2026 00:00
Sources 1
How related:
The campaign was identified on October 4 by researchers at WordPress security platform Patchstack, against users of WPC Product Bundles for WooCommerce.
About this happening:
A WordPress plugin exploitation campaign is using stored XSS in WPC Product Bundles for WooCommerce and Ninja Forms to plant backdoors and create rogue admin...
WordPress plugin stored XSS exploitation campaign targeting WPC Product Bundles for WooCommerce and Ninja Forms
CampaignHow related: The campaign was identified on October 4 by researchers at WordPress security platform Patchstack, against users of WPC Product Bundles for WooCommerce.
About this happening: A WordPress plugin exploitation campaign is using stored XSS in WPC Product Bundles for WooCommerce and Ninja Forms to plant backdoors and create rogue admin...
Ninja Forms stored XSS flaw (CVE-2026-94504)
Vulnerability
H score29
First: 07.10.2026 00:00
Last: 07.10.2026 00:00
Sources 1
How related:
They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
About this happening:
CVE-2026-94504 in Ninja Forms is being exploited on WordPress sites, putting older installs at risk of stored XSS, backdoors, and rogue admin accounts. The...
Ninja Forms stored XSS flaw (CVE-2026-94504)
VulnerabilityHow related: They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.
About this happening: CVE-2026-94504 in Ninja Forms is being exploited on WordPress sites, putting older installs at risk of stored XSS, backdoors, and rogue admin accounts. The...
Timeline
-
07.10.2026 00:00 2 articles · 3h ago
Stored XSS in WPC Product Bundles for WooCommerce plants backdoors and rogue admin access
Exploitation ObservedPatchstack identified exploitation against users of WPC Product Bundles for WooCommerce on October 4, with a stored XSS payload delivered from imgcdn1[.]com running inside an authenticated WordPress session, retrieving administrative nonces, installing a malicious plugin masquerading as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs,” and creating administrator access.
Show sources
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00
-
07.10.2026 00:00 1 articles · 3h ago
Stored XSS in Ninja Forms plants backdoors and rogue admin access
Exploitation ObservedThe next day, the same activity was observed against Ninja Forms, with malicious JavaScript planted in Ninja Forms submissions, executed when a logged-in administrator loaded the content, and used to install the fake “WP Smart Thumbnails” plugin and create administrator access.
Show sources
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00
-
07.10.2026 00:00 1 articles · 3h ago
Patchstack advises upgrading vulnerable WordPress plugins
Mitigation Patch UpdatePatchstack says exploitation is currently limited and advises site administrators to upgrade WPC Product Bundles for WooCommerce to version 8.6.7 or later and Ninja Forms to version 3.15.4 or later, warning that updating the vulnerable plugin prevents further exploitation but does not clean an existing infection.
Show sources
- Ninja Forms plugin flaw exploited to hack WordPress sites — www.bleepingcomputer.com — 07.10.2026 00:00