Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.
Both vulnerabilities received a high severity score and require an authenticated session to exploit. They are tracked as CVE-2026–93836, affecting WPC Product Bundles for WooCommerce versions 8.6.6 and older, and CVE-2026–94504, affecting Ninja Forms versions 3.15.3 and older.
The Ninja Forms plugin for WordPress is installed on more than 500,000 sites and allows creating custom forms without writing code.
