Attackers are exploiting a stored cross-site scripting flaw in Ninja Forms, a WordPress form plugin with more than 500,000 active installations, as part of a campaign that can create hidden administrator access on compromised sites.
Patchstack reported on October 6, 2026, that the same JavaScript payload has been used against two unrelated WordPress plugin vulnerabilities: CVE-2026-93836 in WPC Product Bundles for WooCommerce and CVE-2026-94504 in Ninja Forms. Patchstack said it first saw the payload on October 4 against WPC Product Bundles and then on October 5 through Ninja Forms.
What is affected
The Ninja Forms vulnerability affects versions 3.15.3 and earlier. Patchstack lists version 3.15.4 as the patched release for CVE-2026-94504. WordPress.org currently lists Ninja Forms 3.15.5 as the current release and shows two recent security hardening entries: version 3.15.4 strengthened output escaping in the admin submission edit screen, while version 3.15.5 strengthened sanitization for Paragraph Text (Rich Text) field submissions.
That makes the practical update target the latest available Ninja Forms release, not merely the first fixed version. Patchstack also notes a possible CVE identifier overlap with CVE-2026-92438 and says patching the affected version resolves both identifiers.
| Plugin | Tracked issue | Affected versions | Current update target noted in sources |
|---|---|---|---|
| Ninja Forms | CVE-2026-94504 | 3.15.3 and earlier | 3.15.4 or later; WordPress.org currently lists 3.15.5 |
| WPC Product Bundles for WooCommerce | CVE-2026-93836 | 8.6.6 and earlier | 8.6.7 or later; WordPress.org currently lists 8.7.4 |
How the attack chain works
Patchstack says attackers submit malicious content through the normal Ninja Forms AJAX submission path. The malicious content is stored, then can execute when a privileged user views the affected submission in the WordPress administrative area. Stored scripts in order metadata can pose a similar risk when an administrator reviews an order.
The attacker does not need to steal an administrator cookie in the usual sense. The script runs in the same site context as wp-admin and can make same-origin requests that carry the logged-in administrator’s existing session. Patchstack says the script retrieves administrative nonces from WordPress pages and replays them to perform actions through legitimate WordPress functions.
According to Patchstack’s analysis, the campaign uses that access to install a malicious plugin posing as WP Smart Thumbnails, create administrator access, and call additional persistence code. The same second-stage infrastructure was used in both the WPC Product Bundles and Ninja Forms attempts, which is why Patchstack tied the activity to one campaign. The reported exploitation volume was still limited in Patchstack’s telemetry at publication.
Why patching alone may not clean up an affected site
Updating Ninja Forms closes the known vulnerable path, but a site that was already exploited may still have attacker access.
Patchstack’s analysis says one successful execution can leave four routes back into a site: a visible administrator account, a hidden administrator account, a secret login URL, and an unauthenticated file manager inside the malicious plugin. Patchstack also says removing the vulnerable plugin or even the malicious plugin does not remove some of those persistence mechanisms.
What administrators should check now
Administrators running Ninja Forms should confirm the installed version first. Sites still on 3.15.3 or earlier should be treated as exposed. Sites already updated should still be checked if administrators viewed recent form submissions before patching.
- Plugin versions: update Ninja Forms to the latest available release. If WPC Product Bundles for WooCommerce is installed, update it to the latest available release as well.
- Administrator accounts: review WordPress administrator users through the dashboard and, where possible, directly in the database. The campaign includes a hidden administrator mechanism, so the dashboard alone may not be enough.
- Must-use plugins: inspect
wp-content/mu-pluginsfor unexpected files. Must-use plugins load automatically and do not appear on the regular Plugins screen. - Unexpected plugins: look for a plugin or directory resembling
wp-smart-thumbnails, especially if no one intentionally installed it. - Logs and stored submissions: search web server, WordPress, and security logs for
imgcdn1[.]com,/fz/x.js,/fz/c.php, suspicious Ninja Forms submissions, and unusual administrator actions. - Backups and cleanup: if signs of compromise appear, preserve logs before removing evidence, rotate administrator passwords, review file integrity, and consider a professional malware cleanup or a restore from a trusted backup.

Tech Help Canada Staff researches, writes, and reviews practical content for business owners and professionals. Our coverage spans business, marketing, SEO, technology, and the tools and systems people use to grow and operate online. We focus on clear, useful information backed by research, hands-on experience, and editorial review. Learn more about our team and editorial standards. Need help with something? Contact Us







