CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
HIGHCVE-2026-94504 +1exploitedNATOB2vulnerability

CVE-2026-94504 / CVE-2026-93836, Ninja Forms and WPC Product Bundles for WooCommerce: stored XSS exploited to plant a hidden WordPress administrator and four persistence routes that survive the update

Exploited WordPress plugin XSS ends in a hidden admin and persistence that patching does not remove

Defender actions

  • Update Ninja Forms to 3.15.4 or later and WPC Product Bundles for WooCommerce to 8.6.7 or later on every WordPress site, then check each site for an implant the update does not remove, starting with a comparison of the database's administrator list against the Users screen and an inspection of the must-use plugins directory by content.
  • On any site where an administrator opened a Ninja Forms submission or a WooCommerce order since 2026-10-04 and an implant turns up, rotate all privileged credentials and the WordPress authentication salts and treat the oldest administrator account as compromised, because a login URL planted by the implant authenticates as that account.

Analysis

Patchstack reports two unrelated stored cross-site scripting flaws that deliver the same second-stage script, first seen on 2026-10-04 against WPC Product Bundles for WooCommerce (CVE-2026-93836) and on 2026-10-05 against Ninja Forms (CVE-2026-94504) (Patchstack, 2026-10-06). No account is needed: a numeric-prefixed quantity keeps attacker markup in WooCommerce order data, and a textarea submission sent through the normal form endpoint is stored and rendered without safe encoding in the legacy Ninja Forms submission editor (Patchstack, 2026-10-06). The script runs when a logged-in administrator opens the order or submission, rides that session in wp-admin without reading the cookie, so HttpOnly does not help (Patchstack, 2026-10-06).

With that session it uploads a plugin through WordPress' own installer, creates an administrator and calls a persistence installer (Patchstack, 2026-10-06). Patchstack counts four ways back in: the visible administrator; a second administrator that a dropped must-use plugin hides from the Users list, its filters and its role counts; a login URL, backed by another must-use plugin, that authenticates as the site's oldest administrator; and an unauthenticated file manager in the uploaded plugin that runs only on a direct request and can write files anywhere writable (Patchstack, 2026-10-06). The must-use plugins are backdated to the oldest file time in the WordPress root, so a search for recently changed files misses them (Patchstack, 2026-10-06).

Both flaws were disclosed on 2026-09-22; Patchstack says exploitation volume is limited and that the second stage works with any stored XSS that reaches an administrator (Patchstack, 2026-10-06). The fixed versions are Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7, and updating does not clean an existing infection (BleepingComputer, 2026-10-06).

Triage: a legitimate administrator installing a plugin from a ZIP produces the same plugin-install and user-creation events; the discriminators are that they follow an administrator opening a stored submission or order, that the installed plugin poses as a thumbnail cache and does nothing when WordPress loads it, and that the new administrator is missing from the Users list.

Cited evidence

exploitation volume remains limited in our telemetry

It is a fully privileged administrator the site owner cannot see.

Removing the vulnerable plugin, or even the malicious one, closes none of the last three.

Patchstack 2026-10-06

Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection.

BleepingComputer 2026-10-06

Sources2

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.