CVE-2026-94504
CVSS 7.2 HIGH: ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. EPSS 0.4% (33º percentile).
Vulnerabilità · 5 ore fa
BleepingComputer riferisce che due plugin WordPress, Ninja Forms e WPC Product Bundles for WooCommerce, sono sotto sfruttamento attivo tramite stored XSS: gli attaccanti usano CVE-2026-93836 e CVE-2026-94504 per installare backdoor e creare account admin falsi. Il punto non è più il difetto nel plugin, ma la persistenza che lascia dietro di sé.
Il contenuto malevolo viene salvato nel sito e poi eseguito nel browser di un amministratore come codice fidato del sito stesso. Da lì l’attaccante può agire nella sessione admin e lasciare modifiche stabili, come nuovi account o backdoor, che sopravvivono anche se il trigger visibile viene rimosso.
Per chi gestisce WordPress, questo sposta il problema dalla correzione del bug alla verifica dello stato reale del sito. Se restano account non riconosciuti o componenti nascosti, il compromesso può continuare anche dopo la rimozione del contenuto che lo ha innescato.
CVSS 7.2 HIGH: ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. EPSS 0.4% (33º percentile).
CVSS 7.2 HIGH: the WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… EPSS 0.4% (32º percentile).
1 fonte che coprono questa storia
Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.
Part of the PlainSec briefing for 2026-10-06