Patchstack says attackers are exploiting two unrelated plugin flaws to deliver the same malicious script. It first saw the attacks on October 4. The script is built to leave several ways back into a site, including an admin account that does not show in your Users screen.
Who is affected
Both flaws are stored cross-site scripting bugs. That means an attacker saves malicious script on your site, and it runs when an administrator views the page.
- WPC Product Bundles for WooCommerce through 8.6.6 (CVE-2026-93836). Fixed in 8.6.7.
- Ninja Forms through 3.15.3 (CVE-2026-94504). Fixed in 3.15.4.
Patchstack says two plugins are the confirmed count so far, and more may follow.
What the attack does
The script only works if a logged-in admin triggers it, such as by opening a poisoned form entry. It then uses that admin’s session to install a malicious plugin and create a new administrator account.
Patchstack describes four ways back in: a visible admin account, a hidden admin account, a secret login link that signs in as the original site owner, and a file manager that needs no login. The attackers also backdate files to look old.
What to do
- Update both plugins now if you use them.
- Check your admin list in the database, because the hidden account will not appear in wp-admin.
- Look for a plugin called
wp-smart-thumbnailsand unfamiliar files in/wp-content/mu-plugins/. Do not trust file dates. - Search server logs for requests to
imgcdn1.com. - If you find anything, remove it, then reset all admin passwords and your WordPress security keys.
Patchstack advises treating any affected site as fully breached. Updating the plugin alone does not remove a backdoor that is already installed.
End of article