“The [hidden] account does not appear in Users → All Users, does not appear in the Administrator filter, and is not counted in the totals above the list,” Patchstack explains, adding that “It is a fully privileged administrator the site owner cannot see.”
Timeline and scope: two plugins, two CVEs, one campaign
Researchers at WordPress security platform Patchstack identified a campaign on October 4 that targeted users of WPC Product Bundles for WooCommerce, and observed the same activity against Ninja Forms the next day. Patchstack tied both exploit chains to stored cross-site scripting (XSS) vulnerabilities that require an authenticated session to trigger and that received high severity scores. The issues are tracked as CVE-2026-93836 (WPC Product Bundles for WooCommerce versions 8.6.6 and older) and CVE-2026-94504 (Ninja Forms versions 3.15.3 and older).
The reach of the affected plugins amplifies risk: Ninja Forms is installed on more than 500,000 sites, and WPC Product Bundles for WooCommerce is active on more than 30,000 sites.
How the attack unfolds: stored XSS to malicious plugin installation
According to Patchstack, the attacker plants malicious JavaScript (x.js) in either WooCommerce order data or Ninja Forms submissions. That script is hosted at a single domain — delivered from imgcdn1[.]com — which Patchstack notes as an indicator that the same threat actor carried out the attempts against both plugins.
When a logged-in administrator views the infected content, the stored XSS executes under the administrator’s authenticated WordPress session. The script then retrieves the needed administrative nonces and uses legitimate WordPress functions to install a plugin presented as “WP Smart Thumbnails” version 1.2.4 from “MediaPress Labs,” and to create an administrator account.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildFour persistence and access mechanisms the attacker leaves behind
- A visible administrator account.
- An administrator account concealed from the WordPress user list in the dashboard.
- A secret login URL that authenticates as the site’s oldest existing administrator.
- An unauthenticated file manager accessible through a direct request to the malicious plugin’s main PHP file.
Patchstack notes the file manager cannot execute commands, but it can be used to introduce additional payloads. Even if the WP Smart Thumbnails plugin is later removed, the concealed administrator account and the secret login URL remain functional via separate auxiliary attack plugins. Those auxiliary plugins use backdated timestamps to evade detection, Patchstack says.
What this means for site administrators, plugin maintainers, and security teams
- Site administrators: Patchstack advises upgrading to WPC Product Bundles for WooCommerce version 8.6.7 or later and Ninja Forms 3.15.4 or later. Updating the vulnerable plugin prevents further exploitation, but does not clean an existing infection; administrators are strongly recommended to check for signs of compromise, including invisible administrator accounts, unexpected admin accounts, and unknown plugins.
- Plugin maintainers: the campaign underlines the consequences of stored XSS that requires authenticated access — a high-severity condition when abused to execute administrative actions. Patchstack’s timeline shows how quickly attackers can reuse a single payload (x.js) across different plugins.
- Security teams and incident responders: Patchstack observed the JavaScript payload delivered from imgcdn1[.]com and named the malicious plugin and its false vendor ("WP Smart Thumbnails" v1.2.4 from "MediaPress Labs") — concrete indicators to include in hunts and detection rules. Teams should also look for auxiliary plugins with backdated timestamps and for unauthenticated file manager endpoints tied to the malicious plugin’s main PHP file.
Conclusion
Patchstack describes the exploitation as currently limited, but the mechanics are straightforward and stealthy: a stored XSS that runs as an administrator, a JavaScript dropper (x.js) hosted at imgcdn1[.]com, installation of a masquerading plugin, and multiple persistence options including a completely hidden administrator account and a secret login URL that outlives the visible plugin. Administrators who run Ninja Forms (≤3.15.3) or WPC Product Bundles for WooCommerce (≤8.6.6) should update to the versions Patchstack specifies and perform targeted checks for the indicators described above, because updating alone will not remove any backdoors already established.
Original reporting: https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/




