top of page

WordPress plugin attacks can leave hidden administrator accounts

Writer: Charles Coles
Charles Coles
3 days ago
2 min read

Source announcement date: Patchstack research published on 6 October 2026.


Event dates: Attacks observed against WPC Product Bundles on 4 October and Ninja Forms on 5 October.


WordPress website owners should check two plugins after researchers identified attacks that can leave hidden administrator access behind. Patchstack published its findings on 6 October, following observations against WPC Product Bundles for WooCommerce on 4 October and Ninja Forms on 5 October.


The affected releases are WPC Product Bundles 8.6.6 and earlier, tracked as CVE-2026-93836, and Ninja Forms 3.15.3 and earlier, tracked as CVE-2026-94504. Patchstack describes both as stored cross-site scripting vulnerabilities. This means hostile code is saved in content that the website later displays, rather than running immediately when the attacker submits it.


In this campaign, the code is placed in order information or form submissions. When a logged-in administrator views the affected content, it can use that administrator’s existing session to install a malicious plugin and create accounts. The researchers also found mechanisms for concealing an administrator and providing a secret login route. An apparently normal user list therefore does not establish that the site is clean.

For businesses, unauthorised administrative access could allow someone to change pages, interfere with trading or gain further access to site data. Those are potential consequences, not claims that every website using these plugins has been compromised.


Update WPC Product Bundles to 8.6.7 or later and Ninja Forms to 3.15.4 or later. Crucially, patching does not remove an existing infection. Ask your developer or hosting provider to check Patchstack’s published indicators, including hidden accounts and additional plugin files. Its clean-up guidance includes removing backdoors, reviewing the database and files, and replacing privileged credentials.


Sources: Patchstack’s original investigation and clean-up guidance, BleepingComputer’s additional reporting. The description of the attack’s access requirements follows the original research.

Comments


Top Stories

Stay informed with the latest in cybersecurity. Subscribe to our newsletter for updates.

  • Instagram
  • Facebook
  • Twitter

© 2023 by My Site. Your trusted source for cyber news.

bottom of page