WordPress plugin flaws exploited to install backdoors and create rogue admin accounts

Attackers target Ninja Forms and WPC Product Bundles plugins in coordinated campaign

By LineZotpaper
Published
Read Time2 min
Hackers are exploiting stored cross-site scripting vulnerabilities in two popular WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors, create hidden administrator accounts, and establish persistent access to compromised sites.

The campaign, identified by researchers at Patchstack on October 4 and 5, targets users of the two plugins. The vulnerabilities, tracked as CVE-2026-93836 (WPC Product Bundles) and CVE-2026-94504 (Ninja Forms), are high-severity stored XSS flaws requiring an authenticated session to exploit. Ninja Forms is installed on more than 500,000 sites, while WPC Product Bundles for WooCommerce has over 30,000 active installations.

Attackers deliver a JavaScript payload from imgcdn1[.]com. When a logged-in administrator loads a WooCommerce order or Ninja Forms submission, the script executes using the authenticated session. It then retrieves administrative nonces and uses legitimate WordPress functions to install a malicious plugin masquerading as "WP Smart Thumbnails" version 1.2.4 from "MediaPress Labs," and creates an administrator account.

Patchstack reports that the payload establishes four access mechanisms: a visible admin account, a hidden admin account not visible in the user list, a secret login URL that authenticates as the oldest existing administrator, and an unauthenticated file manager. Even if the malicious plugin is removed, the hidden account and secret login URL persist through auxiliary attack plugins with backdated timestamps.

The researchers note that exploitation is currently limited but advise administrators to update to the latest versions (WPC Product Bundles 8.6.7+, Ninja Forms 3.15.4+). Updating prevents further exploitation but does not clean existing infections. Administrators should check for signs of compromise.

§

Analysis

Why This Matters

  • Over half a million WordPress sites are potentially vulnerable; a successful compromise gives attackers complete control, including the ability to deface sites, steal data, or use them for further attacks.
  • The four persistence mechanisms make cleanup difficult, even if the visible backdoor is removed.

Background

WordPress powers a large portion of the web, and its plugin ecosystem is a common target for attackers. Stored XSS vulnerabilities allow attackers to inject malicious scripts that execute when administrators view certain content. The use of legitimate WordPress functions to install plugins and create accounts makes detection harder, as the actions appear normal. Patchstack is a WordPress security firm that frequently identifies such threats.

Key Perspectives

Site administrators: They face a difficult cleanup process even after patching, as hidden accounts and secret login URLs can remain active without detection. Plugin developers: The vulnerabilities highlight the need for secure coding practices, especially for plugins with millions of installations. Updates are available, but zero-day exploits remain a risk. Security researchers: This campaign demonstrates advanced techniques for persistence, including hidden admin accounts and backdated timestamps, which may become more common.

What to Watch

  • Whether the attackers expand their campaign beyond the two currently targeted plugins.
  • Reports of similar hidden account mechanisms appearing in other WordPress attacks.
  • Server logs or security scanners detecting requests to imgcdn1[.]com or the presence of "WP Smart Thumbnails" plugin.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.