Skip to the stories
Thursday, 8 October 2026
Saved

Next edition

10:55

Headlines

Top Stories

Hackers exploit Ninja Forms and WooCommerce plugin flaws in WordPress

Hackers are actively exploiting cross-site scripting vulnerabilities in two popular WordPress plugins to install backdoors and create unauthorized administrator accounts.

FTMQ Security, written by our newsroom0 views

Share
Picture: BleepingComputer

Hackers are exploiting stored cross-site scripting vulnerabilities in two unrelated WordPress plugins to install backdoors and create rogue administrator accounts, BleepingComputer reported. The attacks target the Ninja Forms plugin and the WPC Product Bundles for WooCommerce plugin. Both flaws require an authenticated session to execute. [1]

The vulnerability in WPC Product Bundles for WooCommerce is tracked as CVE-2026-93836 and affects versions 8.6.6 and older, according to BleepingComputer. The flaw in Ninja Forms is tracked as CVE-2026-94504. Both security issues have received high severity scores. [1]

WordPress is an open-source web content management system used to publish websites, blogs, and online stores. By December 2024, the platform powered 22.52% of the top one million websites. Plugin support was first introduced to the platform in 2004 to enable enhanced customization. [3][4]

Share

In short

  • Hackers are exploiting stored cross-site scripting flaws in Ninja Forms and WPC Product Bundles for WooCommerce.
  • The vulnerabilities allow attackers to create rogue administrator accounts and install backdoors.
  • The targeted flaws are tracked as CVE-2026-93836 and CVE-2026-94504.

Sources

Every paragraph above points to the numbered items it rests on. Read the originals here.

  1. [1]Ninja Forms plugin flaw exploited to hack WordPress sitesBleepingComputer, 1d ago (the report this story comes from)

Background

  1. [2]Ninja Gaiden 4 on Wikipedia
  2. [3]WordPress on Wikipedia
  3. [4]WordPress on Grokipedia

Our newsroom writes these reports with the help of software, from the 4 sources listed and nothing else, and checks them against those sources. Facts can still be wrong or move on; the originals are the record. Spotted a mistake? Write to daniel@monsterkong.com.

Earlier reports of ours on the same people and subjects.

More in Top Stories

Get the day in one email

Reports like this one, the top news of the last 24 hours, every morning. Free, one email a day; readers can comment under every report.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.

Comments

Loading

Join the conversation

Comments are open to readers of our daily email: the top news of the last 24 hours, every morning, free. Sign up and the comment box opens.

Already on the list? Enter the same address and we will send a sign-in link.

By signing up you agree to our terms and privacy policy. Unsubscribe any time.