BlackTree Security · Infrastructure · Automation · AI

WordPress XSS Leaves Backdoors

Two WordPress flaws are being exploited. Patchstack links one payload to WPC Product Bundles and Ninja Forms. The WPC flaw is CVE-2026-93836; the Ninja Forms flaw is CVE-2026-94504.

The administrator view is the trigger

Attackers can store malicious content without logging in, but it runs only after a logged-in administrator opens the affected order or submission.

The WPC flaw stores script in WooCommerce order metadata through a numeric-prefixed quantity. The Ninja Forms flaw stores anonymous textarea content that is rendered without safe encoding in the legacy submission editor.

The payload installs a fake plugin, hidden administrators, a secret login route and a file manager.

Update, then investigate

The official directory lists Ninja Forms 3.15.5 as current. Version 3.15.4 first recorded stronger output escaping in the administrative submission editor. It lists WPC Product Bundles 8.7.3 as current. Version 8.6.7 records the earlier vulnerability fix, while 8.7.3 adds sanitisation and whitelisting to prevent stored XSS.

Patching does not remove hidden accounts, mu-plugins or backdoor persistence already installed. BlackTree’s earlier WordPress incident analysis supports an owner-led review of unexpected administrators, plugins and file changes, evidence preservation before cleanup, and credential and authentication-salt rotation during containment. It covered a different plugin family and campaign, not a shared cause.

What remains unknown

Patchstack reports limited telemetry, no victim total and no attribution. Its two confirmed vectors do not prove automatic compromise or exploitation of every stored-XSS flaw.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *