Hackers exploit Ninja Forms and WooCommerce plugin flaws in WordPress
Hackers are actively exploiting cross-site scripting vulnerabilities in two popular WordPress plugins to install backdoors and create unauthorized administrator accounts.
FTMQ Security, written by our newsroom0 views

Hackers are exploiting stored cross-site scripting vulnerabilities in two unrelated WordPress plugins to install backdoors and create rogue administrator accounts, BleepingComputer reported. The attacks target the Ninja Forms plugin and the WPC Product Bundles for WooCommerce plugin. Both flaws require an authenticated session to execute. [1]
The vulnerability in WPC Product Bundles for WooCommerce is tracked as CVE-2026-93836 and affects versions 8.6.6 and older, according to BleepingComputer. The flaw in Ninja Forms is tracked as CVE-2026-94504. Both security issues have received high severity scores. [1]
WordPress is an open-source web content management system used to publish websites, blogs, and online stores. By December 2024, the platform powered 22.52% of the top one million websites. Plugin support was first introduced to the platform in 2004 to enable enhanced customization. [3][4]
In short
- Hackers are exploiting stored cross-site scripting flaws in Ninja Forms and WPC Product Bundles for WooCommerce.
- The vulnerabilities allow attackers to create rogue administrator accounts and install backdoors.
- The targeted flaws are tracked as CVE-2026-93836 and CVE-2026-94504.
Sources
Every paragraph above points to the numbered items it rests on. Read the originals here.
- [1]Ninja Forms plugin flaw exploited to hack WordPress sitesBleepingComputer, 1d ago (the report this story comes from)
Background
- [2]Ninja Gaiden 4 on Wikipedia
- [3]WordPress on Wikipedia
- [4]WordPress on Grokipedia
Our newsroom writes these reports with the help of software, from the 4 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.
Related from FTMQ Security
Earlier reports of ours on the same people and subjects.
- CISA adds actively exploited Citrix NetScaler zero day to KEV catalogCybercrime and Scams, 2d ago
More in Top Stories
- Attackers hijack top level domains to obtain unauthorized Google security certificates6m ago
- Discord security bot Double Counter breached exposing user email addresses6m ago
- FBI warns ongoing FortiBleed attacks target Fortinet VPNs and lock out administrators6m ago
- MonsterCloud owner charged over secret ransomware payments6m ago
- Ransomware group BYOD claims data breach exposing Trump Mobile subscriber records6m ago
- FBI removes Accenture contractor following Oracle PeopleSoft data breach1d ago
Get the day in one email
Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments
Loading
Join the conversation
Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.
Already on the list? Enter the same address and we will send a sign-in link.
By signing up you agree to our terms and privacy policy. Unsubscribe any time.