CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

WPC Product Bundles for WooCommerce up to 8.6.6, unauthenticated stored XSS via the quantity parameter, exploited (Patchstack, 2026-10-06) to plant a hidden administrator; fixed in 8.6.7

cve · CVE-2026-93836 single-source

Coverage
1
first 2026-10-07 → last 2026-10-07
Latest activity
2026-10-07
Exploited WordPress plugin XSS ends in a hidden admin and persistence that patching does not remove
Peak priority
high
1 high
Targets
technology
sectors: technology, public-sector
Sources cited
2
2 hosts

Action items (2)

Do-now tasks recorded on the entries about CVE-2026-93836, newest first. Check the date before acting on an older one.

  • Update Ninja Forms to 3.15.4 or later and WPC Product Bundles for WooCommerce to 8.6.7 or later on every WordPress site, then check each site for an implant the update does not remove, starting with a comparison of the database's administrator list against the Users screen and an inspection of the must-use plugins directory by content.
    2026-10-07CVE-2026-94504 +1
  • On any site where an administrator opened a Ninja Forms submission or a WooCommerce order since 2026-10-04 and an implant turns up, rotate all privileged credentials and the WordPress authentication salts and treat the oldest administrator account as compromised, because a login URL planted by the implant authenticates as that account.
    2026-10-07CVE-2026-94504 +1

Defender insights

What each entry about CVE-2026-93836 tells a defender to do, newest first.

2026-10-07HIGHexploitedExploited WordPress plugin XSS ends in a hidden admin and persistence that patching does not remove

Exposure · triage · detection

Story timeline

  1. 2026-10-07CVE-2026-94504 / CVE-2026-93836, Ninja Forms and WPC Product Bundles for WooCommerce: stored XSS exploited to plant a hidden WordPress administrator and four persistence routes that survive the update
    trending-vulnerabilitiesExploited WordPress plugin XSS ends in a hidden admin and persistence that patching does not remove
ATT&CK techniques (8 across 6 tactics)

8 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • ExecutionCommand and Scripting Interpreter: JavaScript
  • PersistenceCreate Account · Server Software Component: Web Shell
  • StealthObfuscated Files or Information · Indicator Removal: Timestomp
  • CollectionBrowser Session Hijacking
  • Command and ControlIngress Tool Transfer

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-07/ninja-forms-wpc-bundles-stored-xss-hidden-admin-campaign · ATT&CK page ↗

Execution TA0002

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-10-07/ninja-forms-wpc-bundles-stored-xss-hidden-admin-campaign · ATT&CK page ↗

Persistence TA0003

T1136Create Account×1

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Evidence: 2026-10-07/ninja-forms-wpc-bundles-stored-xss-hidden-admin-campaign · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-10-07/ninja-forms-wpc-bundles-stored-xss-hidden-admin-campaign · ATT&CK page ↗

Stealth TA0005

T1027Obfuscated Files or Information×1

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Evidence: 2026-10-07/ninja-forms-wpc-bundles-stored-xss-hidden-admin-campaign · ATT&CK page ↗

T1070.006Indicator Removal: Timestomp×1

Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder and blend malicious files with legitimate files.

Evidence: 2026-10-07/ninja-forms-wpc-bundles-stored-xss-hidden-admin-campaign · ATT&CK page ↗

Collection TA0009

T1185Browser Session Hijacking×1

Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques.

Evidence: 2026-10-07/ninja-forms-wpc-bundles-stored-xss-hidden-admin-campaign · ATT&CK page ↗

Command and Control TA0011

T1105Ingress Tool Transfer×1

Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).

Evidence: 2026-10-07/ninja-forms-wpc-bundles-stored-xss-hidden-admin-campaign · ATT&CK page ↗

Entries about WPC Product Bundles for WooCommerce up to 8.6.6, unauthenticated stored XSS via the quantity parameter, exploited (Patchstack, 2026-10-06) to plant a hidden administrator; fixed in 8.6.7 (1)

2026-10-07 · view entry permalink →

HIGHCVE-2026-94504 +1exploitedNATOB2

CVE-2026-94504 / CVE-2026-93836, Ninja Forms and WPC Product Bundles for WooCommerce: stored XSS exploited to plant a hidden WordPress administrator and four persistence routes that survive the update

Patchstack reports two unrelated stored cross-site scripting flaws that deliver the same second-stage script, first seen on 2026-10-04 against WPC Product Bundles for WooCommerce (CVE-2026-93836) and on 2026-10-05 against Ninja Forms (CVE-2026-94504) (Patchstack, 2026-10-06). No account is needed: a numeric-prefixed quantity keeps attacker markup in WooCommerce order data, and a textarea submission sent through the normal form endpoint is stored and rendered without safe encoding in the legacy Ninja Forms submission editor (Patchstack, 2026-10-06). The script runs when a logged-in administrator opens the order or submission, rides that session in wp-admin without reading the cookie, so HttpOnly does not help (Patchstack, 2026-10-06).

With that session it uploads a plugin through WordPress' own installer, creates an administrator and calls a persistence installer (Patchstack, 2026-10-06). Patchstack counts four ways back in: the visible administrator; a second administrator that a dropped must-use plugin hides from the Users list, its filters and its role counts; a login URL, backed by another must-use plugin, that authenticates as the site's oldest administrator; and an unauthenticated file manager in the uploaded plugin that runs only on a direct request and can write files anywhere writable (Patchstack, 2026-10-06). The must-use plugins are backdated to the oldest file time in the WordPress root, so a search for recently changed files misses them (Patchstack, 2026-10-06).

Both flaws were disclosed on 2026-09-22; Patchstack says exploitation volume is limited and that the second stage works with any stored XSS that reaches an administrator (Patchstack, 2026-10-06). The fixed versions are Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7, and updating does not clean an existing infection (BleepingComputer, 2026-10-06).

Triage: a legitimate administrator installing a plugin from a ZIP produces the same plugin-install and user-creation events; the discriminators are that they follow an administrator opening a stored submission or order, that the installed plugin poses as a thumbnail cache and does nothing when WordPress loads it, and that the new administrator is missing from the Users list.

exploitation volume remains limited in our telemetry

It is a fully privileged administrator the site owner cannot see.

Removing the vulnerable plugin, or even the malicious one, closes none of the last three.

Patchstack 2026-10-06

Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection.

BleepingComputer 2026-10-06
vulnerability07 Oct 04:45Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • bleepingcomputer.com1 (50%)
  • patchstack.com1 (50%)