CVE-2026-94504
CVSS 7.2 HIGH: ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. EPSS 0.4% (33rd percentile).
Vulnerabilities & Exploits · Web App Attack
Hackers are exploiting stored cross-site scripting flaws in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins to install backdoors and create rogue admin accounts. The issues are tracked as CVE-2026-93836 and CVE-2026-94504.
The attack stores malicious input in a post or form field, then waits for a logged-in administrator to load it in the browser as trusted site code. That lets the attacker act through the admin session, which is enough to add accounts and plant persistent changes instead of just defacing a page.
For WordPress sites that use either plugin, the compromise can outlive the visible trigger: removing the bad content does not necessarily remove the hidden access. The reporting does not say how widely the exploitation is spreading, but it does show the cleanup problem is now about account and backdoor control, not just the original XSS vector.
1 source · Oct 6
CVSS 7.2 HIGH: ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. EPSS 0.4% (33rd percentile).
CVSS 7.2 HIGH: the WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… EPSS 0.4% (32nd percentile).
BleepingComputer
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.
originalPart of the PlainSec briefing for 2026-10-06
Every edition of this story: WordPress Plugin XSS Leaves Backdoors Behind