WordPress Campaign Leverages Two XSS Vulnerabilities for Persistent Backdoor Access
A sophisticated campaign is exploiting two distinct stored XSS vulnerabilities in popular WordPress plugins to install a malicious plugin, create hidden admin accounts, and establish persistent backdoor access.

A coordinated cyberattack campaign has been observed actively exploiting two separate stored Cross-Site Scripting (XSS) vulnerabilities in widely used WordPress plugins. The campaign, first detected on October 4, 2026, utilizes a single JavaScript payload delivered through distinct attack vectors targeting CVE-2026-93836 in WPC Product Bundles for WooCommerce and CVE-2026-94504 in Ninja Forms. This unified payload indicates a centralized operation aiming for deep system compromise.
The primary objective of the campaign is not merely to exploit the initial vulnerabilities but to establish persistent access and control over compromised WordPress sites. The delivered JavaScript payload acts as a post-exploitation implant designed to run within the browser of an authenticated administrator. By leveraging the administrator's active session, the script abuses legitimate WordPress functionalities to install a malicious plugin, create a new administrator account, and implement further hidden persistence mechanisms.
The first vulnerability exploited was CVE-2026-93836, an unauthenticated stored XSS flaw in WPC Product Bundles for WooCommerce (versions prior to 8.6.6). Attackers injected malicious JavaScript into the woosb_ids[…][qty] parameter, which was then stored in WooCommerce order metadata and rendered unsafely. This allowed the attacker's script, hosted on imgcdn1.com, to execute within the administrative dashboard when an administrator viewed the affected order details.
Shortly after, the same JavaScript payload was observed being delivered via CVE-2026-94504, a stored XSS vulnerability in Ninja Forms (versions prior to 3.15.3). In this instance, attackers submitted malicious data through the Ninja Forms AJAX endpoint, embedding JavaScript within form fields. When an administrator viewed the submission in the legacy editor, the injected script would execute, again fetching the x.js payload from the attacker-controlled domain.
Once executed, the x.js script, lightly obfuscated, initiates a check-in with the command-and-control (C2) server at https://imgcdn1.com/fz/c.php. The C2 response dictates which post-exploitation stages have already been completed, allowing the malware to proceed with installing a malicious plugin and creating a new administrator account. A critical aspect of this attack is its ability to bypass standard security measures like HttpOnly cookies, as the JavaScript operates within the browser's existing session context, making same-origin requests that automatically include authentication.
The installed malicious plugin is particularly concerning, featuring an unauthenticated file manager and a second script designed for deeper persistence. This script creates a hidden administrator account, invisible to the standard WordPress Users screen, and establishes a backdoor login URL. To further evade detection, the malware backdates its own files, making them appear older than the WordPress installation itself, thus obscuring its presence.
The campaign's reliance on two distinct vulnerabilities to deliver a single, sophisticated payload highlights the evolving tactics of attackers targeting the vast WordPress ecosystem. The ability to establish hidden administrative accounts and backdoor access poses a significant threat to website integrity and data security, requiring immediate attention from site administrators and plugin developers alike.
While the specific vulnerabilities have been addressed in updated versions of the plugins (version 8.6.7 for WPC Product Bundles and 3.15.4 for Ninja Forms), the active exploitation observed underscores the critical need for prompt patching and ongoing vigilance against such advanced persistent threats.