Attackers are actively exploiting stored cross-site scripting vulnerabilities in two WordPress plugins to install malicious software, create hidden administrator accounts and establish multiple methods of persistent access.
The campaign targets Ninja Forms and WPC Product Bundles for WooCommerce, which have more than 500,000 and 30,000 active installations respectively. Patchstack first detected exploitation against WPC Product Bundles on October 4 and observed the same malicious payload targeting Ninja Forms one day later.
The two vulnerabilities are:
- CVE-2026-94504 in Ninja Forms through version 3.15.3
- CVE-2026-93836 in WPC Product Bundles for WooCommerce through version 8.6.6
Both carry a CVSS score of 7.1. Exploitation volume was limited in Patchstack’s telemetry at publication time, but the shared payload is designed to work with other WordPress stored-XSS vulnerabilities as well.
ATTACKERS DO NOT NEED A WORDPRESS ACCOUNT
Both vulnerabilities allow an unauthenticated attacker to place malicious JavaScript into information that is stored by a vulnerable WordPress site.
In Ninja Forms attacks, the payload is submitted through ordinary form fields. In WPC Product Bundles attacks, malicious markup is inserted into WooCommerce order data.
The code does not execute immediately. It remains stored until a logged-in administrator opens the affected form submission or order in the WordPress dashboard.
Because the script runs inside the administrator’s authenticated browser session, it can use legitimate WordPress functions and security tokens to perform actions with the administrator’s privileges. The attacker does not need to steal the administrator’s session cookie.
MALWARE CREATES FOUR ROUTES BACK INTO THE SITE
Researchers found that the injected script downloads a malicious plugin disguised as “WP Smart Thumbnails” version 1.2.4 from a purported developer named “MediaPress Labs.”
The plugin and associated scripts establish four access methods:
- A visible administrator account
- A second administrator account hidden from the WordPress user list
- A secret URL that logs the attacker in as the site’s oldest administrator
- An unauthenticated file manager inside the malicious plugin
The file manager can be used to add further malicious files. Separate must-use plugins preserve the hidden account and secret login mechanism even if the fake WP Smart Thumbnails plugin is removed.
Attackers also backdate malicious files so they appear older than the WordPress installation, making simple searches for recently modified files less reliable.

