Active exploitation of stored cross-site scripting vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce plugins has enabled attackers to install backdoors and create rogue admin accounts, bleepingcomputer.com reported.
Two Plugins, One Identical JavaScript Payload
The campaign emerged when researchers at WordPress security platform Patchstack identified malicious activity targeting users of WPC Product Bundles for WooCommerce on October 4. By the next day, identical activity targeted Ninja Forms. Both flaws require an authenticated session to exploit and carry high severity scores. They are tracked as CVE-2026-93836 for WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026-94504 for Ninja Forms versions 3.15.3 and older.
The Ninja Forms plugin is installed on more than 500,000 sites, allowing users to build custom forms without writing code. Meanwhile, WPC Product Bundles for WooCommerce is active on over 30,000 sites, enabling merchants to group products into bundles. Despite the difference in core functionality, both attack vectors deployed the exact same JavaScript payload from imgcdn1[.]com, pointing to a single threat actor behind both operations.
How the Backdoor Deployment Executes
Attackers inject malicious JavaScript (x.js) directly into WooCommerce order data or Ninja Forms submissions. When a logged-in site administrator loads the affected content, the injected script executes within their active administrative session. The script then captures the necessary administrative nonces and invokes legitimate WordPress functions to install a malicious plugin.

This rogue plugin masquerades as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs.” Once installed, the payload and PHP scripts establish four distinct access mechanisms:
- A visible administrator account.
- An administrator account entirely concealed from the WordPress dashboard user list.
- A secret login URL that authenticates automatically as the site’s oldest existing administrator.
- An unauthenticated file manager accessible via direct requests to the malicious plugin’s main PHP file.
While the unauthenticated file manager cannot execute arbitrary server commands directly, it provides an interface to introduce further malicious payloads. Patchstack noted that the concealed administrator account does not appear in Users → All Users, does not appear in the Administrator filter, and is not counted in the totals above the list,
making it a fully privileged account that site owners cannot see.
Persistence Mechanisms Beyond Plugin Removal
Removing the fake WP Smart Thumbnails plugin from an infected WordPress site does not eradicate the threat. The hidden administrator account and the secret login URL continue to operate as persistent access vectors. Attackers achieve this longevity by deploying separate auxiliary attack plugins equipped with backdated timestamps designed to evade detection by standard integrity monitors.
Immediate Remediation and Administrative Checks
Patchstack advises site administrators to upgrade immediately to patched software versions: WPC Product Bundles for WooCommerce version 8.6.7 or later, and Ninja Forms version 3.15.4 or later. However, updating vulnerable plugins only stops fresh exploitation vectors; it does not clean an existing system compromise.
Site administrators must audit their installations thoroughly for unauthorized user accounts, anomalous administrator credentials, and unexpected auxiliary plugins bearing backdated timestamps.