Security firm Patchstack reported on October 6, 2026 that attackers are exploiting flaws in two WordPress plugins: Ninja Forms and WPC Product Bundles for WooCommerce. When an administrator opens a tampered form submission or order, the attack creates an administrator account that the dashboard does not show. Fixed versions have been available since September.
What we know
- Who is reporting it: Patchstack, which sells a firewall for WordPress, in an analysis dated October 6, 2026. This is third-party research based on the sites it protects, not an advisory from WordPress.org.
- Which plugins: Ninja Forms, with more than 500,000 active installations, through version 3.15.3 (CVE-2026-94504). And WPC Product Bundles for WooCommerce, with more than 30,000, through 8.6.6 (CVE-2026-93836). Both are stored cross-site scripting (XSS) flaws. The attacker needs no account on the site. Patchstack rates each at CVSS 7.1.
- Since when: Patchstack saw the first attempt on October 4 against WPC Product Bundles and on October 5 against Ninja Forms, carrying the same code.
- How it gets in: the attacker submits a form or places an order with tampered content. When a logged-in administrator opens it in the dashboard, the code acts with that person's permissions. It does not need to steal the password or the cookie: it uses the open session, according to the analysis.
- What it leaves behind: a fake plugin called "WP Smart Thumbnails", version 1.2.4, by a supposed "MediaPress Labs". And four ways back in: a visible administrator, a hidden administrator, a login address that signs in as the site's oldest administrator, and a file manager with no password.
- Why you cannot see it: the hidden account does not appear under Users or in the counts above the list. A file in the must-use plugins folder (mu-plugins) hides it, and that file cannot be deactivated from the dashboard. The files also carry a fake old date, Patchstack says.
- Scale: Patchstack says "exploitation volume remains limited in our telemetry" and that it expects more plugins to be affected. It does not say how many sites were compromised or who is behind it.
- Patches: Ninja Forms fixed the flaw in version 3.15.4, dated September 21, 2026 in its changelog on WordPress.org. WPC Product Bundles fixed it in 8.6.7. On October 7 the current versions were 3.15.5 and 8.7.4, and both branches carry a later fix for the same type of flaw (3.15.5 and 8.7.3), according to those changelogs.
What changes and what doesn't
The urgency changes: a patched flaw is now being exploited. Between the fixed Ninja Forms release (September 21) and the first attack seen against that plugin (October 5), 14 days went by, by this article's count.
WordPress core does not change: the flaw sits in two plugins, not in WordPress or WooCommerce. WordPress 7.1.3 does not fix it, because plugins update separately.
One point matters more than the rest: updating today closes the door, but it does not clean a site that was already hit. According to Patchstack, removing the vulnerable plugin, or even the fake one, closes none of the other three ways in.
How to tell if this affects you
It does if your site or store runs Ninja Forms or WPC Product Bundles for WooCommerce. Steps 4 to 6 apply to any WordPress site, because Patchstack expects the same code to arrive through other plugins. Eight steps, no command line needed:
- Check whether you have them. In the dashboard, open Plugins → Installed Plugins and look for both names.
- Check the version. Ninja Forms 3.15.3 or older and WPC Product Bundles 8.6.6 or older are vulnerable.
- Update to the latest release, not the minimum: 3.15.5 and 8.7.4 as of October 7. The Ninja Forms listing requires WordPress 6.9 and PHP 7.4 or higher: on an older WordPress the dashboard may not offer the update, so update WordPress first.
- Look for the fake plugin. If "WP Smart Thumbnails" is in the list and nobody installed it, that is the clearest sign. Check your host's file manager too: `wp-content/plugins/wp-smart-thumbnails/`.
- Open the `wp-content/mu-plugins/` folder. Patchstack names two files: `class-wp-token-validate.php` and one starting with `class-wp-query-`. Do not sort by date: the dates are forged.
- Count administrators in the database, not in the dashboard. In phpMyAdmin or your host's database tool, open the users table (`wp_users`; the prefix may differ) and compare it with Users → All Users. An account that is in the table but not in the dashboard is the hidden one. Other signs, per Patchstack: an `@wordpress.org` email address, or a name like "support", "updater", "maintenance" or "backup".
- If you find anything, deleting the plugin is not enough. Patchstack says to remove the unauthorized accounts and plugins, clear the files from mu-plugins, delete two database options (`fz_emer_done_v1` and `fz_emer_login_tokens`) and rotate administrator passwords and WordPress security salts. Treat the oldest administrator's password as compromised.
- If someone else maintains the site, ask two things: "Which Ninja Forms version am I on?" and "Who checked the mu-plugins folder?".
Until you update, avoid opening form submissions or orders with an administrator account. That is this article's precaution. The full indicator list and the exact database query are in Patchstack's analysis.
Related: WordPress 7.1.3 Fixes 7 Security Flaws: Update Your Site Now
Sources
- Patchstack, "Four ways back in: the WordPress XSS campaign that hides its own admin account", October 6, 2026
- WordPress.org, Ninja Forms plugin listing and changelog
- WordPress.org, WPC Product Bundles for WooCommerce plugin listing and changelog
Updates: this note will be extended if Patchstack confirms more affected plugins, or if the authors of Ninja Forms or WPC Product Bundles publish their own advisory.