In a coordinated security campaign that has sent shockwaves through the WordPress ecosystem, threat actors are leveraging high-severity stored cross-site scripting (XSS) vulnerabilities to systematically compromise thousands of websites. Security researchers at Patchstack have identified that the campaign targets two widely used plugins—Ninja Forms and WPC Product Bundles for WooCommerce—to facilitate unauthorized administrative access and long-term site persistence.
The discovery highlights a sophisticated level of automation and planning, as the attackers utilize a unified delivery infrastructure to inject malicious code into site databases. Once an administrator interacts with the compromised content, the site is effectively surrendered to the threat actor, allowing them to install backdoors and create "invisible" administrative accounts that bypass standard dashboard visibility.
Main Facts: The Anatomy of the Attack
The core of this security incident lies in the exploitation of stored XSS vulnerabilities. Unlike reflected XSS, where a malicious link must be clicked by a victim, stored XSS allows an attacker to inject malicious code directly into a website’s database—typically via form submissions or product metadata.
The Vulnerable Components
Two specific vulnerabilities are being weaponized in this campaign:
- CVE-2026-93836: Affecting WPC Product Bundles for WooCommerce (versions 8.6.6 and older). This plugin is a staple for e-commerce sites, allowing for the grouping of products. It is currently active on over 30,000 websites.
- CVE-2026-94504: Affecting the highly popular Ninja Forms plugin (versions 3.15.3 and older). With an installation base exceeding 500,000 sites, this plugin is a major target for attackers seeking to exploit the trust users place in form-building tools.
Both vulnerabilities require an authenticated session to execute; however, the attackers have successfully bypassed this hurdle by targeting scenarios where site administrators or staff members are likely to interact with data input fields or order management dashboards.
The Malicious Payload
The campaign relies on a consistent JavaScript payload (x.js) served from the domain imgcdn1[.]com. Upon execution within an administrator’s browser, the script performs a series of unauthorized actions:
- Nonce Harvesting: The script scrapes the necessary security tokens (nonces) required to perform administrative actions.
- Plugin Injection: Using these tokens, the script triggers the installation of a rogue plugin masquerading as "WP Smart Thumbnails" (version 1.2.4), purportedly from a developer labeled "MediaPress Labs."
- Privilege Escalation: The script automatically generates a new administrative account, granting the attacker full control over the WordPress backend.
Chronology of the Incident
The identification of this campaign was the result of proactive monitoring by the Patchstack security team. The timeline of the exploitation demonstrates a rapid, methodical rollout of the attack vector across different plugin ecosystems.
- October 4, 2026: Patchstack researchers first observed malicious activity targeting users of WPC Product Bundles for WooCommerce. The pattern suggested an automated effort to inject JavaScript payloads into WooCommerce order data.
- October 5, 2026: Within 24 hours of the initial discovery, the threat actors pivoted. Researchers identified identical activity—utilizing the same malicious JavaScript infrastructure—being directed at the Ninja Forms plugin.
- October 6–7, 2026: Analysis confirmed that the attackers were not merely stealing data but were focused on establishing permanent persistence. By this time, it was clear that the "WP Smart Thumbnails" plugin was a secondary stage designed to provide a multi-layered backdoor.
- Ongoing: Security patches have been released by the developers of both affected plugins. However, the window of opportunity remains open for sites that have not yet performed manual updates or security audits.
Supporting Data and Technical Analysis
The sophistication of this attack extends beyond the initial injection. Once the "WP Smart Thumbnails" plugin is installed, it initiates a series of obfuscation techniques to ensure the attacker retains access even if the site owner notices the plugin and attempts to delete it.
The "Invisible" Admin Problem
One of the most alarming findings by Patchstack is the creation of a "ghost" administrator. Through specific database manipulation, the attackers ensure that the newly created account does not appear in the standard "Users > All Users" list. It is excluded from the administrator filter and is not included in the total user count, effectively hiding the account from the sight of the site administrator.
Multi-Layered Persistence
The campaign establishes four distinct mechanisms for maintaining access:

- Rogue Plugin: The primary vehicle for initial access and command execution.
- Hidden Admin Account: A secondary backdoor that allows the attacker to log in as a privileged user even if the plugin is disabled.
- File Manager Backdoors: While these may not always execute commands directly, they are used to plant additional "sleeper" payloads that can be activated later.
- Auxiliary Plugins: Even after the primary "WP Smart Thumbnails" plugin is removed, separate auxiliary plugins—often disguised with backdated timestamps—ensure that the attacker maintains a "phone home" connection to their command-and-control server.
Official Responses and Remediation
The security community has responded quickly to neutralize the immediate threat, though the burden of remediation falls squarely on the shoulders of individual site administrators.
Patching the Vulnerabilities
Developers for both Ninja Forms and WPC Product Bundles have issued critical security updates. Administrators are urged to take the following actions immediately:
- Ninja Forms: Update to version 3.15.4 or later.
- WPC Product Bundles: Update to version 8.6.7 or later.
Beyond Updating: The Cleanup
Patchstack has issued a stern warning: Updating the plugin only prevents further exploitation. It does not remove existing backdoors, malicious admin accounts, or the "WP Smart Thumbnails" plugin if it has already been installed.
Administrators should perform a thorough forensic sweep of their WordPress installations, specifically looking for:
- Unexpected plugins in the
/wp-content/plugins/directory, especially those claiming to be "WP Smart Thumbnails." - Unrecognized user accounts that may be hidden from the standard dashboard view (checking the
wp_usersandwp_usermetatables in the database is recommended). - Any unauthorized JavaScript files or modified core files that may indicate secondary persistence.
Implications for the WordPress Ecosystem
The events of October 2026 serve as a stark reminder of the risks associated with the plugin-heavy nature of modern web development. With over 500,000 sites affected by the Ninja Forms vulnerability alone, the scale of this campaign is significant.
The Cost of Convenience
The ease with which attackers can weaponize legitimate plugin features to gain administrative control illustrates a critical tension in the WordPress community: the desire for "no-code" functionality versus the security risks inherent in complex third-party code. When a plugin allows for dynamic data entry—like form builders or e-commerce bundle tools—it creates a massive attack surface that must be constantly guarded against XSS and injection attacks.
The Threat of "Stealth" Persistence
The emergence of "invisible" admin accounts represents a shift in attacker strategy. By prioritizing stealth over immediate disruption (such as defacement or ransomware), attackers can maintain a foothold for months or even years. This allows them to harvest sensitive customer data, use the server for spam distribution, or redirect traffic to malicious phishing sites without the site owner ever suspecting a breach.
A Call for Proactive Security
As AI-powered attacks become faster and more accurate at identifying vulnerable targets, the time between a vulnerability being disclosed and an active exploit is shrinking. The two-hour turnaround in this campaign—from the first sign of an attack on one plugin to its expansion to another—demonstrates that manual security patching is no longer sufficient.
For enterprise users and site owners, the recommendation is clear: implement automated security monitoring, perform regular vulnerability scans, and maintain strict backups. The "security blueprint" of the future must be one of constant validation, where site integrity is checked at machine speed, and the assumption of a "clean" site is never taken for granted.
In conclusion, while the immediate vulnerabilities have been patched, the lingering effects of this campaign will likely be felt for months. Site administrators must move beyond simple updates and conduct deep-level audits to ensure their installations remain free of the hidden backdoors that have become the hallmark of this sophisticated threat actor.







