Security1 publisherNot yet confirmed elsewhere2 min readPublished
One actor exploits two unrelated WordPress plugins to plant backdoors on live sites
One actor is exploiting stored XSS flaws in two WordPress plugins, one installed on more than 500,000 sites, to plant backdoors and rogue administrator accounts. Patchstack says updating the plugins blocks further exploitation but will not clean a site that is already compromised.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Both bugs are rated high severity and need an authenticated session; they are tracked as CVE-2026-93836 in WPC Product Bundles for WooCommerce 8.6.6 and earlier and CVE-2026-94504 in Ninja Forms 3.15.3 and earlier.
- Patchstack logged the WPC Product Bundles attacks on October 4 and the Ninja Forms attacks the next day, both pulling the same JavaScript payload from imgcdn1[.]com.
- WPC Product Bundles for WooCommerce, the smaller of the two targets, is active on more than 30,000 WordPress sites.
- The payload, named x.js, is planted in WooCommerce order data or Ninja Forms submissions and runs in the browser of any logged-in administrator who opens that content.
- Fixes shipped in WPC Product Bundles 8.6.7 and Ninja Forms 3.15.4, and Patchstack rates exploitation as limited so far.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- capability The attacker gets full administrator control without any admin credentials, from content a logged-in user is permitted to submit.
- constraint Pulling the rogue plugin is not enough to recover a hit site, because the access survives in separate backdated helper plugins, so remediation has to go deeper than the plugin screen.
- exposure A clean-looking Users screen is not proof of safety here, so operators cannot clear a site by reviewing the dashboard alone.
Once the script runs it retrieves the administrative nonces WordPress uses to authorize privileged actions, then calls the platform's own functions to install a plugin posing as 'WP Smart Thumbnails' version 1.2.4, attributed to a vendor called 'MediaPress Labs,' and to create an administrator account. [10]
From there the payload and the plugin's PHP code open four separate ways back in: a visible administrator account, a second administrator account hidden from the WordPress user list, a secret login URL that authenticates as the site's oldest existing administrator, and an unauthenticated file manager reached by requesting the plugin's main PHP file directly. [11] The file manager cannot run commands, but it can be used to stage more payloads. [12]
Deleting WP Smart Thumbnails does not close the breach. The hidden account and the secret login URL keep working through separate helper plugins whose timestamps are backdated to avoid notice. [13] The hidden admin is the hardest piece to find. It does not show in the Users list, the Administrator filter, or the dashboard's user totals. [15] "It is a fully privileged administrator the site owner cannot see," Patchstack said. [14]
For sites that ran the older versions, Patchstack recommends looking for signs of compromise [19]: the fake plugin [10], an administrator account the owner did not create [11], and the backdated helper plugins that preserve access. [13]
What to watch
- Whether Patchstack's 'limited' exploitation count climbs once scanners start flagging the imgcdn1[.]com payload.
- Whether other plugins begin serving the same x.js from imgcdn1[.]com, widening the campaign beyond these two.
- Removal guidance for the hidden admin and the secret login URL that survive deletion of WP Smart Thumbnails.