Find notable cyber news and cases, enriched with sources, timelines, and signals.

WPC Product Bundles for WooCommerce stored XSS actively exploited (CVE-2026-93836)

Vulnerability
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-93836 in WPC Product Bundles for WooCommerce is being actively exploited on WordPress sites, letting attackers plant backdoors and create rogue administrator accounts. The flaw affects version 8.6.6 and older and requires an authenticated session. Patchstack identified the activity on October 4, 2026, with exploitation continuing into October 5.

Related Happenings

WordPress plugin stored XSS exploitation campaign targeting WPC Product Bundles for WooCommerce and Ninja Forms

Campaign
H score29 First: 07.10.2026 00:00 Last: 07.10.2026 00:00 Sources 1

How related: The campaign was identified on October 4 by researchers at WordPress security platform Patchstack, against users of WPC Product Bundles for WooCommerce.

About this happening: A WordPress plugin exploitation campaign is using stored XSS in WPC Product Bundles for WooCommerce and Ninja Forms to plant backdoors and create rogue admin...

Ninja Forms stored XSS flaw (CVE-2026-94504)

Vulnerability
H score29 First: 07.10.2026 00:00 Last: 07.10.2026 00:00 Sources 1

How related: They are tracked as CVE-2026-93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504, affecting Ninja Forms versions 3.15.3 and older.

About this happening: CVE-2026-94504 in Ninja Forms is being exploited on WordPress sites, putting older installs at risk of stored XSS, backdoors, and rogue admin accounts. The...

Timeline

  1. 07.10.2026 00:00 2 articles · 3h ago

    Stored XSS in WPC Product Bundles for WooCommerce plants backdoors and rogue admin access

    Exploitation Observed

    Patchstack identified exploitation against users of WPC Product Bundles for WooCommerce on October 4, with a stored XSS payload delivered from imgcdn1[.]com running inside an authenticated WordPress session, retrieving administrative nonces, installing a malicious plugin masquerading as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs,” and creating administrator access.

    Show sources
  2. 07.10.2026 00:00 1 articles · 3h ago

    Stored XSS in Ninja Forms plants backdoors and rogue admin access

    Exploitation Observed

    The next day, the same activity was observed against Ninja Forms, with malicious JavaScript planted in Ninja Forms submissions, executed when a logged-in administrator loaded the content, and used to install the fake “WP Smart Thumbnails” plugin and create administrator access.

    Show sources
  3. 07.10.2026 00:00 1 articles · 3h ago

    Patchstack advises upgrading vulnerable WordPress plugins

    Mitigation Patch Update

    Patchstack says exploitation is currently limited and advises site administrators to upgrade WPC Product Bundles for WooCommerce to version 8.6.7 or later and Ninja Forms to version 3.15.4 or later, warning that updating the vulnerable plugin prevents further exploitation but does not clean an existing infection.

    Show sources