Stored XSS in WordPress plugins leads to site takeovers
🛡️ Researchers observed threat actors exploiting stored cross-site scripting (XSS) flaws in two WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create hidden admin accounts. Both high-severity issues require an authenticated session and are tracked as CVE-2026-94504 and CVE-2026-93836. The campaign delivered identical JavaScript from imgcdn1[.]com to plant a malicious plugin and establish multiple persistence mechanisms, including a secret login URL and a concealed administrator account.
