Active WordPress XSS Campaign – Hidden Admin Persistence via Ninja Forms and WPC Product Bundles
Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake WP Smart Thumbnails plugin, hide an administrator account, and add persistent backdoor access.
Patchstack has observed active exploitation of two unauthenticated stored cross-site scripting vulnerabilities to compromise WordPress administrator sessions and establish multiple persistence mechanisms. The campaign targets WPC Product Bundles for WooCommerce through 8.6.6 and Ninja Forms through 3.15.3.
Campaign summary
| First observed | October 4, 2026 |
|---|---|
| Initial access | Unauthenticated stored XSS that executes when an administrator views affected content |
| Vulnerabilities | CVE-2026-93836 and CVE-2026-94504 |
| Affected products | WPC Product Bundles for WooCommerce ≤ 8.6.6; Ninja Forms ≤ 3.15.3 |
| Fixed versions | WPC Product Bundles 8.6.7; Ninja Forms 3.15.4 |
| Observed payload host | imgcdn1.com |
| Malicious plugin | wp-smart-thumbnails |
| Exploitation status | Active exploitation observed by Patchstack |
Initial access vulnerabilities
WPC Product Bundles for WooCommerce ≤ 8.6.6
CVE-2026-93836 is an unauthenticated stored XSS issue in bundle quantity handling. An attacker can place markup into WooCommerce order metadata, which may execute later when an administrator reviews the affected order. Version 8.6.7 contains the security fix; WordPress.org currently offers newer releases and sites should update to the latest available version.
Ninja Forms ≤ 3.15.3
CVE-2026-94504 is an unauthenticated stored XSS issue affecting non-rich-text textarea submissions displayed in the legacy administrative submission editor. The injected script executes only when a privileged user opens the malicious submission. Ninja Forms 3.15.4 strengthened output escaping; the current WordPress.org release is newer and should be preferred.
What happens after the XSS executes
The campaign’s JavaScript runs inside the trusted origin of the compromised WordPress site. It does not need to steal the administrator’s cookie. Instead, it uses the administrator’s already authenticated browser session to load privileged pages, collect WordPress nonces, install a plugin, create an administrator, and trigger additional persistence.
The observed package installs as wp-smart-thumbnails and pretends to be “WP Smart Thumbnails 1.2.4” by “MediaPress Labs.” Patchstack found that it contains an unauthenticated file manager, a persistence installer, a hidden administrator mechanism, and a backdoor login route.
Indicators of compromise
- Network or log references to
imgcdn1.com,/fz/x.js, or/fz/c.php. - Plugin directory
/wp-content/plugins/wp-smart-thumbnails/. - Files
wp-smart-thumbnails.phpandemer-run.phpin that directory. - Must-use plugin
/wp-content/mu-plugins/class-wp-token-validate.php. - Must-use plugins matching
/wp-content/mu-plugins/class-wp-query-*.php. - Database options
fz_emer_done_v1orfz_emer_login_tokens. - Requests to
wp-login.phpcarrying the_wploginquery parameter. - Browser Local Storage keys beginning with
__xp_v9_. - A local administrator account using an
@wordpress.orgemail address or a routine-looking username such as support, updater, maintenance, or backup.
The malware deliberately backdates files. Modification time is therefore not a reliable exclusion signal.
Immediate remediation
- Update WPC Product Bundles for WooCommerce to the latest available release, at minimum 8.6.7.
- Update Ninja Forms to the latest available release, at minimum 3.15.4.
- Block outbound and inbound access involving
imgcdn1.comwhile investigating. IP-only blocks are insufficient because most observed source addresses were Tor exits. - Preserve a forensic copy before removing files or accounts.
- Inspect plugins, must-use plugins, database administrators, options, scheduled tasks, and access logs using the checks below.
- If any indicator is present, treat the site as fully compromised: remove persistence, rebuild affected software from clean packages, rotate all privileged credentials and API keys, replace WordPress salts, and review neighboring hosting accounts.
Defensive checks
Check installed versions:
wp plugin get woo-product-bundle --fields=name,status,version,update,update_version
wp plugin get ninja-forms --fields=name,status,version,update,update_version
Inventory regular and must-use plugins:
wp plugin list --fields=name,status,version,update
wp plugin list --status=must-use --fields=name,status,version
Because the malware can hide an account through a must-use plugin, query administrators directly from the database. Replace the table prefix if necessary:
SELECT u.ID, u.user_login, u.user_email, u.user_registered
FROM wp_users AS u
JOIN wp_usermeta AS m ON m.user_id = u.ID
WHERE m.meta_key = 'wp_capabilities'
AND m.meta_value LIKE '%administrator%';
Check for the campaign’s database state without modifying it:
SELECT option_name
FROM wp_options
WHERE option_name IN ('fz_emer_done_v1', 'fz_emer_login_tokens');
Search logs and the WordPress filesystem for indicators:
grep -R -n -E "imgcdn1\.com|/fz/x\.js|/fz/c\.php|_wplogin" /var/log/nginx /var/log/apache2 2>/dev/null
find wp-content -type f \( -path "*/wp-smart-thumbnails/*" -o -name "class-wp-token-validate.php" -o -name "class-wp-query-*.php" \) -print
Cleanup cautions
Deleting the malicious wp-smart-thumbnails directory alone is not sufficient. The hidden administrator and must-use plugins can survive independently, and the backdoor token options can preserve a magic-login path. Remove every confirmed persistence component only after evidence is preserved, then rotate credentials and verify the site from a known-clean environment.
Administrators who viewed suspicious WooCommerce orders or Ninja Forms submissions during the campaign window should clear browser site data after server-side remediation and reset their WordPress sessions.
Sources
- Patchstack: active campaign analysis and indicators
- WordPress.org: WPC Product Bundles changelog
- WordPress.org: Ninja Forms changelog
- Patchstack: Ninja Forms vulnerability record
WPDeeply did not discover this campaign or these vulnerabilities. This advisory paraphrases Patchstack’s public research and official plugin changelogs.