WPDeeply
Download free plugin
Plugin Security

Active WordPress XSS Campaign – Hidden Admin Persistence via Ninja Forms and WPC Product Bundles

Attackers are exploiting stored XSS flaws in Ninja Forms and WPC Product Bundles to install a fake WP Smart Thumbnails plugin, hide an administrator account, and add persistent backdoor access.

Ninja Forms plugin affected by the active CVE-2026-94504 stored XSS campaign

Patchstack has observed active exploitation of two unauthenticated stored cross-site scripting vulnerabilities to compromise WordPress administrator sessions and establish multiple persistence mechanisms. The campaign targets WPC Product Bundles for WooCommerce through 8.6.6 and Ninja Forms through 3.15.3.

Campaign summary

First observed October 4, 2026
Initial access Unauthenticated stored XSS that executes when an administrator views affected content
Vulnerabilities CVE-2026-93836 and CVE-2026-94504
Affected products WPC Product Bundles for WooCommerce ≤ 8.6.6; Ninja Forms ≤ 3.15.3
Fixed versions WPC Product Bundles 8.6.7; Ninja Forms 3.15.4
Observed payload host imgcdn1.com
Malicious plugin wp-smart-thumbnails
Exploitation status Active exploitation observed by Patchstack

Initial access vulnerabilities

WPC Product Bundles for WooCommerce ≤ 8.6.6

CVE-2026-93836 is an unauthenticated stored XSS issue in bundle quantity handling. An attacker can place markup into WooCommerce order metadata, which may execute later when an administrator reviews the affected order. Version 8.6.7 contains the security fix; WordPress.org currently offers newer releases and sites should update to the latest available version.

Ninja Forms ≤ 3.15.3

CVE-2026-94504 is an unauthenticated stored XSS issue affecting non-rich-text textarea submissions displayed in the legacy administrative submission editor. The injected script executes only when a privileged user opens the malicious submission. Ninja Forms 3.15.4 strengthened output escaping; the current WordPress.org release is newer and should be preferred.

What happens after the XSS executes

The campaign’s JavaScript runs inside the trusted origin of the compromised WordPress site. It does not need to steal the administrator’s cookie. Instead, it uses the administrator’s already authenticated browser session to load privileged pages, collect WordPress nonces, install a plugin, create an administrator, and trigger additional persistence.

The observed package installs as wp-smart-thumbnails and pretends to be “WP Smart Thumbnails 1.2.4” by “MediaPress Labs.” Patchstack found that it contains an unauthenticated file manager, a persistence installer, a hidden administrator mechanism, and a backdoor login route.

Indicators of compromise

  • Network or log references to imgcdn1.com, /fz/x.js, or /fz/c.php.
  • Plugin directory /wp-content/plugins/wp-smart-thumbnails/.
  • Files wp-smart-thumbnails.php and emer-run.php in that directory.
  • Must-use plugin /wp-content/mu-plugins/class-wp-token-validate.php.
  • Must-use plugins matching /wp-content/mu-plugins/class-wp-query-*.php.
  • Database options fz_emer_done_v1 or fz_emer_login_tokens.
  • Requests to wp-login.php carrying the _wplogin query parameter.
  • Browser Local Storage keys beginning with __xp_v9_.
  • A local administrator account using an @wordpress.org email address or a routine-looking username such as support, updater, maintenance, or backup.

The malware deliberately backdates files. Modification time is therefore not a reliable exclusion signal.

Immediate remediation

  1. Update WPC Product Bundles for WooCommerce to the latest available release, at minimum 8.6.7.
  2. Update Ninja Forms to the latest available release, at minimum 3.15.4.
  3. Block outbound and inbound access involving imgcdn1.com while investigating. IP-only blocks are insufficient because most observed source addresses were Tor exits.
  4. Preserve a forensic copy before removing files or accounts.
  5. Inspect plugins, must-use plugins, database administrators, options, scheduled tasks, and access logs using the checks below.
  6. If any indicator is present, treat the site as fully compromised: remove persistence, rebuild affected software from clean packages, rotate all privileged credentials and API keys, replace WordPress salts, and review neighboring hosting accounts.

Defensive checks

Check installed versions:

wp plugin get woo-product-bundle --fields=name,status,version,update,update_version
wp plugin get ninja-forms --fields=name,status,version,update,update_version

Inventory regular and must-use plugins:

wp plugin list --fields=name,status,version,update
wp plugin list --status=must-use --fields=name,status,version

Because the malware can hide an account through a must-use plugin, query administrators directly from the database. Replace the table prefix if necessary:

SELECT u.ID, u.user_login, u.user_email, u.user_registered
FROM wp_users AS u
JOIN wp_usermeta AS m ON m.user_id = u.ID
WHERE m.meta_key = 'wp_capabilities'
  AND m.meta_value LIKE '%administrator%';

Check for the campaign’s database state without modifying it:

SELECT option_name
FROM wp_options
WHERE option_name IN ('fz_emer_done_v1', 'fz_emer_login_tokens');

Search logs and the WordPress filesystem for indicators:

grep -R -n -E "imgcdn1\.com|/fz/x\.js|/fz/c\.php|_wplogin" /var/log/nginx /var/log/apache2 2>/dev/null
find wp-content -type f \( -path "*/wp-smart-thumbnails/*" -o -name "class-wp-token-validate.php" -o -name "class-wp-query-*.php" \) -print

Cleanup cautions

Deleting the malicious wp-smart-thumbnails directory alone is not sufficient. The hidden administrator and must-use plugins can survive independently, and the backdoor token options can preserve a magic-login path. Remove every confirmed persistence component only after evidence is preserved, then rotate credentials and verify the site from a known-clean environment.

Administrators who viewed suspicious WooCommerce orders or Ninja Forms submissions during the campaign window should clear browser site data after server-side remediation and reset their WordPress sessions.

Sources

WPDeeply did not discover this campaign or these vulnerabilities. This advisory paraphrases Patchstack’s public research and official plugin changelogs.

WPdeeply

WPDeeply is the site's editorial account for WordPress security advisories, plugin risk research, and remediation guides. Articles under this byline are checked against vendor changelogs, CVE records, vulnerability database entries, and the WPDeeply editorial policy before publication.