Ninja Forms plugin flaw exploited to hack WordPress sites

Executive Summary

Hackers are exploiting stored cross‑site scripting (XSS) vulnerabilities in the Ninja Forms and WPC Product Bundles for WooCommerce WordPress plugins to install backdoors and create rogue administrator accounts, enabling full site compromise.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-10-06T21:00:27+00:00 - Category: threat-intel

Original Description: Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]

"We should all be thankful for those people who rekindle the inner spirit."

— Albert Schweitzer
Source: Bleeping Computer