Hackers Exploit Ninja Forms and WPC Product Bundles Flaws to Backdoor WordPress Sites
A single threat actor is actively exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins — Ninja Forms and WPC Product Bundles for WooCommerce — to hijack administrator sessions, install a malicious plugin, and plant at least four separate backdoor mechanisms on compromised sites, according to WordPress security platform Patchstack. The campaign was first observed against WPC Product Bundles for WooCommerce on October 4, 2026, and expanded to target Ninja Forms the very next day, October 5, 2026. Ninja Forms is installed on more than 500,000 WordPress sites, and WPC Product Bundles runs on more than 30,000 sites, putting a combined install base of roughly 530,000+ sites at risk until patched.
Incident Details
| Attribute | Value |
|---|---|
| Targets | Ninja Forms (form builder) and WPC Product Bundles for WooCommerce (product bundling plugin) |
| Vulnerability type | Stored cross-site scripting (XSS), authenticated-admin execution |
| CVE identifiers | CVE-2026-94504 (Ninja Forms), CVE-2026-93836 (WPC Product Bundles) |
| Affected versions | Ninja Forms ≤3.15.3; WPC Product Bundles for WooCommerce ≤8.6.6 |
| Patched versions | Ninja Forms 3.15.4+; WPC Product Bundles 8.6.7+ |
| Public disclosure | September 22, 2026 |
| Exploitation start | October 4, 2026 (WPC Product Bundles), October 5, 2026 (Ninja Forms) |
| Combined install base | 530,000+ active WordPress sites |
| Payload infrastructure | imgcdn1.com (registered October 1, 2026) |
| Malicious plugin dropped | "WP Smart Thumbnails" v1.2.4, slug wp-smart-thumbnails |
| Discovered by | Patchstack |
How the Attack Works
The two vulnerabilities
Neither flaw requires an unauthenticated attacker to breach the site directly — both rely on tricking a logged-in administrator into viewing attacker-controlled content, at which point the injected script executes with full admin privileges.
| CVE | Plugin | Root Cause |
|---|---|---|
| CVE-2026-93836 | WPC Product Bundles for WooCommerce (≤8.6.6) | A quantity field that begins with a valid numeric value passes a float-cast validation check while retaining attacker-controlled HTML markup. The unsanitized value is stored verbatim in WooCommerce order metadata under the _woosb_ids key and later rendered without escaping when an admin views the order. |
| CVE-2026-94504 | Ninja Forms (≤3.15.3) | Non-rich-text textarea form submissions are stored without safe HTML encoding and rendered unsafely in the plugin's legacy administrative submission editor, allowing injected JavaScript to execute when an admin opens the submission. |
From injected script to full takeover
Once an administrator's session triggers the stored payload, the injected JavaScript — delivered from https://imgcdn1.com/fz/x.js, a roughly 19KB script — runs with the privileges of that logged-in session and carries out a scripted takeover sequence:
- Harvest admin nonces — the script reads WordPress security nonces out of the current admin page to forge authenticated requests.
- Install a malicious plugin — using legitimate WordPress plugin-upload functions (not an exploit), the script installs a plugin disguised as "WP Smart Thumbnails" version 1.2.4, attributed to a fake developer, "MediaPress Labs."
- Call back to C2 — the dropped plugin communicates with a command-and-control endpoint at
https://imgcdn1.com/fz/c.phpto receive further instructions and credentials. - Establish persistence through four independent access paths (below), so the attacker retains access even if any single component is discovered and removed.
Four backdoor access paths
Patchstack's analysis identified four distinct, overlapping persistence mechanisms planted by the malicious plugin:
| Mechanism | Description |
|---|---|
| Visible administrator account | A standard WordPress admin account created through /wp-admin/user-new.php, with username/password supplied by the attacker's C2 server |
| Hidden administrator account | A second admin account created by a dropped file (emer-run.php) and concealed from the Users screen by must-use plugins that rewrite the underlying SQL queries |
| Secret "magic login" URL | A backdoor reachable at a URL pattern resembling /wp-login.php?_wplogin= followed by a token value, which authenticates the requester as the site's oldest administrator account without a password |
| Unauthenticated file manager | A packed file-management API bundled inside the malicious plugin, offering list, upload, delete, rename, and save operations over HTTP with no authentication check of any kind |
Because the hidden-account logic and login-bypass token validation run as must-use plugins (mu-plugins), they load automatically on every page request and are not visible in the standard Plugins screen — meaning the backdoors can survive deletion of the "WP Smart Thumbnails" plugin itself. Observed artifacts include the options fz_emer_done_v1 and fz_emer_login_tokens, mu-plugin files such as class-wp-query- followed by a random hex string and class-wp-token-validate.php, and a browser localStorage key prefix of __xp_v9_.
Attribution signals
Patchstack reports that the same JavaScript payload and infrastructure (imgcdn1.com) appeared in both the WPC Product Bundles campaign and the Ninja Forms campaign, strongly suggesting a single threat actor is running both operations against otherwise unrelated plugins — likely selected simply because both had recently disclosed, unpatched stored-XSS bugs that could be reliably automated. Hidden and visible rogue admin accounts observed in the wild used generic dictionary usernames — such as support, updater, maintenance, and backup — paired with spoofed @wordpress.org email addresses to blend in with legitimate maintenance activity. Malicious traffic has been observed originating from Tor exit nodes and a small set of additional source IPs, consistent with an attacker deliberately obscuring the operation's true origin.
Impact Assessment
| Impact Area | Description |
|---|---|
| Admin account compromise | Full WordPress administrator access via at least one visible and one hidden rogue account per compromised site |
| Persistence | Four overlapping backdoor mechanisms mean removing the obvious malicious plugin does not evict the attacker |
| Unauthorized file access | The bundled file manager allows arbitrary file upload/read/delete with no authentication |
| Scale of exposure | 530,000+ combined active installs across the two plugins before patching |
| Detection difficulty | Hidden admin account and login-bypass logic run as must-use plugins, invisible in the standard Plugins list |
| Downstream risk | Full admin access typically enables malware injection, SEO spam, credential theft, data exfiltration, or resale of site access |
Recommendations
For WordPress site administrators
- Update Ninja Forms to version 3.15.4 or later and WPC Product Bundles for WooCommerce to version 8.6.7 or later immediately — both patches close the stored-XSS root cause.
- Do not assume removing a suspicious plugin resolves the incident. Because persistence is split across must-use plugins, a database table entry, and a hidden account, treat any site that ran a vulnerable version as potentially fully compromised.
- Manually inspect the
/wp-content/mu-plugins/directory for unfamiliar files, particularly anything named with aclass-wp-query-prefix orclass-wp-token-validate.php— these are not standard WordPress core or plugin files. - Audit the full administrator user list (not just the Users screen, which can be filtered by a hidden mu-plugin) directly against the
wp_usersdatabase table for accounts you did not create. - Search the
wp_optionstable for the keysfz_emer_done_v1andfz_emer_login_tokensand remove them after confirming compromise. - Look for a plugin named "WP Smart Thumbnails" (slug
wp-smart-thumbnails, attributed to "MediaPress Labs") and remove it — but only as one step in a full incident response, not as the sole remediation.
For security and incident response teams
- Block outbound and inbound traffic to
imgcdn1.comand its subpaths (/fz/x.js,/fz/c.php) at the network or WAF layer. - Review web server access logs for requests to
/wp-login.phpcontaining a_wploginquery parameter, and for any request pattern matching the unauthenticated file-manager API bundled in the dropped plugin. - Reset credentials and rotate WordPress secret keys/salts on any site confirmed compromised, since nonce material may have been harvested by the injected script.
- When restoring from backup, verify the backup predates the October 2026 compromise window and re-scan it before reuse.
For plugin developers and hosting providers
- Treat any form-input or order-metadata field that is rendered in an admin-facing view as a high-risk XSS surface — admin sessions carry the broadest privileges on the site, making admin-viewed stored XSS equivalent to a privilege-escalation bug in practice.
- Managed WordPress hosts should consider proactively scanning customer sites for the IOCs above and for outdated Ninja Forms/WPC Product Bundles versions, given the speed between disclosure (September 22) and mass exploitation (October 4–5).
Key Takeaways
- A single threat actor is exploiting stored XSS flaws in two unrelated plugins — CVE-2026-94504 (Ninja Forms ≤3.15.3) and CVE-2026-93836 (WPC Product Bundles for WooCommerce ≤8.6.6) — to seize WordPress admin sessions.
- The attack chain hijacks an administrator's authenticated session to install a disguised plugin, "WP Smart Thumbnails", which plants four independent backdoors: a visible admin account, a hidden admin account, a password-less "magic login" URL, and an unauthenticated file manager.
- Persistence survives removal of the obvious malicious plugin because key backdoor logic runs as must-use plugins, which are invisible on the standard Plugins screen.
- Exploitation began October 4, 2026 against WPC Product Bundles and spread to Ninja Forms on October 5, 2026, roughly two weeks after both flaws were publicly disclosed on September 22, 2026.
- Combined, the two plugins run on more than 530,000 active WordPress sites, and shared payload infrastructure at imgcdn1.com links both campaigns to the same operator.
- Site owners must update to Ninja Forms 3.15.4+ and WPC Product Bundles 8.6.7+ and treat any previously vulnerable site as potentially compromised, not just unpatched.