Attackers are exploiting a flaw in Ninja Forms, a WordPress contact form plugin with more than 500,000 active installations, to take over websites. WordPress security firm Patchstack reported the campaign on 6 October 2026. A fix has been available since 21 September, so the sites at risk are those that have not installed recent plugin updates.
The same campaign also uses a flaw in WPC Product Bundles for WooCommerce, a plugin used by online shops. Together, Patchstack puts the two plugins at about 530,000 sites.
What happened
According to Patchstack's analysis, the Ninja Forms flaw is tracked as CVE-2026-94504 and affects version 3.15.3 and older. It is a stored cross-site scripting bug: an attacker who does not need an account can submit a form containing hidden code. The code sits in the site's database until an administrator opens that submission in the WordPress dashboard. It then runs in the administrator's browser, with the administrator's permissions.
Patchstack says the attackers use that moment to install a fake plugin called "WP Smart Thumbnails" version 1.2.4 and set up several ways back into the site. It describes four: a visible administrator account, a hidden administrator account that does not appear in the WordPress Users screen, a secret login link that signs in as the site's oldest administrator, and a file manager that needs no password. In Patchstack's words: "A single successful execution of the stored XSS leaves the attacker with four independent routes back into the site, only one of which is visible from the WordPress dashboard."
The WooCommerce plugin flaw, CVE-2026-93836, affects WPC Product Bundles for WooCommerce version 8.6.6 and older and works the same way, through order data. Patchstack rates both flaws as high severity and describes the observed volume of attacks as limited when it published. BleepingComputer reported the campaign the same day.
Which versions are safe
The plugin's WordPress.org listing shows that Ninja Forms 3.15.4, released on 21 September 2026, strengthened output escaping on the admin screen used to edit submissions, which is where this attack runs. Version 3.15.5, released on 28 September, added further protection against stored cross-site scripting in Paragraph Text fields. Patchstack's advice is to run 3.15.4 or later; the latest version listed is 3.15.5.
For the WooCommerce plugin, the fixed version is 8.6.7 or later.
Who is affected
Anyone running a WordPress site with Ninja Forms 3.15.3 or older, or WPC Product Bundles 8.6.6 or older, is exposed. That includes small business sites on shared hosting, where the site owner rather than the host is usually responsible for plugin updates. Sites where nobody logs in to the dashboard to read form entries are less likely to trigger the code, but the stored submission stays in the database until someone does.
What to do now
- Update the plugins. Install the latest Ninja Forms (3.15.5 at the time of writing) and WPC Product Bundles 8.6.7 or later.
- Turn on automatic plugin updates. WordPress has allowed site owners to switch on automatic updates plugin by plugin since version 5.5, from the Plugins screen. The WordPress documentation says auto-updates run twice a day by default, and that if the controls are missing, the feature may have been "partially or completely deactivated by your hosting company or by a plugin." If that is the case on your site, ask your host how plugin updates are handled.
- Look for signs of a break-in. Patchstack lists what to check, including a plugin folder named wp-smart-thumbnails, unfamiliar files in the wp-content/mu-plugins folder, and administrator accounts you did not create. Because one account is hidden from the dashboard, Patchstack recommends checking the user list directly in the database. A host's support team or a developer can do this for you.
- Treat an infected site as fully compromised. Patchstack warns that updating stops new infections but does not remove an existing one, and that deleting the fake plugin alone leaves the other back doors working. It advises removing unknown accounts and files, then changing passwords and WordPress security keys.
- Keep backups. The WordPress documentation recommends regular automatic backups before enabling auto-updates, so a site can be rolled back if something goes wrong.
What it means if you are choosing web hosting
Most WordPress attacks of this kind rely on sites that have fallen behind on updates, and the fix here was out more than two weeks before the campaign was reported. When comparing hosting plans, it is worth asking each provider whether it applies plugin updates for you, whether it runs malware scanning, how often it takes backups and how long it keeps them, and whether its support will help clean an infected site. Managed WordPress plans often include some of these, while basic shared hosting usually leaves them to the customer. Check each provider's terms rather than assuming.
What is still unknown
- How many sites have been compromised. Patchstack called the volume limited at publication but did not give a number.
- Who is behind the campaign and what the attackers plan to do with the sites they control.
- Whether more plugins with similar flaws will be added to the campaign. Patchstack confirmed exploitation of at least two.
- Reports differ on one detail: BleepingComputer's summary describes the attacks as needing an authenticated session, while Patchstack's analysis says the attacker does not need to be logged in, and that the code runs once a logged-in administrator views the data. This article follows Patchstack, the original researcher.