Vulnerabilities · 5h ago

WordPress Plugin XSS Leaves Backdoors Behind

Hackers are exploiting stored cross-site scripting flaws in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins to install backdoors and create rogue admin accounts. The issues are tracked as CVE-2026-93836 and CVE-2026-94504.

The attack stores malicious input in a post or form field, then waits for a logged-in administrator to load it in the browser as trusted site code. That lets the attacker act through the admin session, which is enough to add accounts and plant persistent changes instead of just defacing a page.

For WordPress sites that use either plugin, the compromise can outlive the visible trigger: removing the bad content does not necessarily remove the hidden access. The reporting does not say how widely the exploitation is spreading, but it does show the cleanup problem is now about account and backdoor control, not just the original XSS vector.

CVE-2026-94504

NVD KEV

CVSS 7.2 HIGH: ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. EPSS 0.4% (33rd percentile).

CVE-2026-93836

NVD KEV

CVSS 7.2 HIGH: the WPC Product Bundles for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the… EPSS 0.4% (32nd percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-10-06

Editions

Related stories