NEWS · OCTOBER 6, 2026 · SECURITY

Ninja Forms and WPC Product Bundles flaws are being used to plant admin accounts owners cannot see

On October 6, 2026 Patchstack described a campaign that pushes a single JavaScript payload through stored XSS bugs in two separate WordPress plugins: Ninja Forms (CVE-2026-94504) and WPC Product Bundles for WooCommerce (CVE-2026-93836). Once an administrator opens the tainted content, the script borrows that session to install a fake plugin and add an admin account that never shows up on the Users screen.

01 · WHAT HAPPENED?

One malicious script, two different ways in

Patchstack's analysis, dated October 6, 2026, says the payload first turned up on October 4 in an attempt aimed at CVE-2026-93836 in WPC Product Bundles for WooCommerce. A day later the same payload arrived again, this time via CVE-2026-94504 in Ninja Forms. Affected releases are 8.6.6 and earlier for WPC Product Bundles and 3.15.3 and earlier for Ninja Forms. Patchstack puts the install base at 500K for Ninja Forms and 30K for WPC Product Bundles, and rates both bugs at CVSS 7.1. BleepingComputer covered the story the same day.

In both cases the script is fetched from imgcdn1.com/fz/x.js. According to Patchstack, that domain was registered on October 1, 2026, while the two flaws had been disclosed publicly on September 22. The loader is written differently for each plugin, yet the second stage always comes from the same server, and that shared infrastructure is what links the two attacks into one campaign. BleepingComputer likewise reads the common domain as a sign of a single threat actor. Neither source names the attacker or ties them to a country.

02 · DETAILS

The two sources disagree on whether a login is needed

On the question of whether an attacker needs to be logged in, the two sources say different things, and this article reports both with attribution rather than settling it. Patchstack, the primary source, classifies both bugs as unauthenticated stored XSS and lists the initial access mode as unauthenticated as well. In the model it describes, the attacker submits data, WordPress keeps it, and the payload fires when an administrator later views that record. BleepingComputer, on the other hand, writes that both flaws require an authenticated session to exploit. Where the two accounts overlap: the code runs with a logged-in administrator's session at the moment that administrator opens the WooCommerce order data or the Ninja Forms submission.

Patchstack explains that the script never takes the admin's cookie; requests it sends from the same origin carry the session automatically. It harvests the nonces it needs from admin pages and then uses WordPress's own plugin installer to add a fake plugin presented as WP Smart Thumbnails 1.2.4 from MediaPress Labs. The end state is four independent routes back in: an administrator visible in the dashboard; a second administrator removed from the Users screen, the Administrator filter and the user totals; a covert login URL that signs the holder in as the site's oldest administrator; and a file manager reachable by direct request with no password at all. Patchstack sums up the hidden account this way: "It is a fully privileged administrator the site owner cannot see." The hidden account and the secret login URL are kept alive by must-use plugins dropped into wp-content/mu-plugins; these never appear on the Plugins screen, and their file dates are set back to match the oldest file in the WordPress root folder.

03 · WHY IT MATTERS

Patching closes the hole, not the door already opened

The attack waits for a routine moment in an administrator's day: opening an order or a form entry. Patchstack argues that which plugin supplies the first bug hardly matters afterwards, since every later step is the same once the script is running in an admin context. That is why the company believes the attackers are collecting stored XSS flaws, and it cautions that the two it has confirmed may not be the final tally. Patchstack also points back to September 2026, when a core XSS bug that needed no login was patched in WordPress 7.1.1; we covered that release on September 19.

Cleanup is the critical part. As BleepingComputer reports, updating blocks further exploitation but leaves an existing infection in place, and even deleting WP Smart Thumbnails does not stop the hidden account or the secret login URL from working. The recommended steps: move WPC Product Bundles to 8.6.7 or later (Patchstack bases that version on the vendor's changelog) and Ninja Forms to 3.15.4 or later; search logs for imgcdn1.com, /fz/x.js and /fz/c.php; and, because the hidden account is invisible in the dashboard, list administrators directly from the database and compare the result with what wp-admin shows. Patchstack adds that an @wordpress.org email address, or an account with a routine name such as support, updater or maintenance, is a further warning sign. The company says exploitation is limited for now; neither source gives a count of compromised sites.

04 · TÜRKİYE

The sources say nothing about Türkiye, so this section is commentary

Neither source mentions Türkiye, sites based in the country or any local institution. What follows is not drawn from the sources; it is explicitly UNALSOFT commentary.

Ninja Forms powers contact forms and WPC Product Bundles runs inside WooCommerce stores, so local small business sites and small online shops built on WordPress may well use them too. The unknowns, one by one: how many sites in Türkiye run either plugin, whether any site in the country has been compromised, and whether a local institution will issue a warning about this campaign. On the practical side, our view is that in small businesses the person opening form entries and orders is often the site administrator, so doing the update and the database check of administrator accounts on the same day is a sensible step.

The UNALSOFT view

We read this less as one plugin's bug and more as a limit on trusting what the admin dashboard shows. The striking part of the campaign is that its persistence is built specifically to stay out of view, so the assumption that updating the plugin ends the problem does not hold here. The more plugins a WordPress site carries, the more of the screens an administrator opens every day can turn into a possible entry point. That is why in our web design work we treat plugin selection, update tracking and checking admin accounts outside the dashboard as part of the maintenance that continues after handover.

Is the admin list on your WordPress site really complete?

A short conversation is enough to review your plugin versions and administrator accounts together.

Message on WhatsApp