The campaign, identified by researchers at Patchstack on October 4 and 5, targets users of the two plugins. The vulnerabilities, tracked as CVE-2026-93836 (WPC Product Bundles) and CVE-2026-94504 (Ninja Forms), are high-severity stored XSS flaws requiring an authenticated session to exploit. Ninja Forms is installed on more than 500,000 sites, while WPC Product Bundles for WooCommerce has over 30,000 active installations.
Attackers deliver a JavaScript payload from imgcdn1[.]com. When a logged-in administrator loads a WooCommerce order or Ninja Forms submission, the script executes using the authenticated session. It then retrieves administrative nonces and uses legitimate WordPress functions to install a malicious plugin masquerading as "WP Smart Thumbnails" version 1.2.4 from "MediaPress Labs," and creates an administrator account.
Patchstack reports that the payload establishes four access mechanisms: a visible admin account, a hidden admin account not visible in the user list, a secret login URL that authenticates as the oldest existing administrator, and an unauthenticated file manager. Even if the malicious plugin is removed, the hidden account and secret login URL persist through auxiliary attack plugins with backdated timestamps.
The researchers note that exploitation is currently limited but advise administrators to update to the latest versions (WPC Product Bundles 8.6.7+, Ninja Forms 3.15.4+). Updating prevents further exploitation but does not clean existing infections. Administrators should check for signs of compromise.