← Blog · · df00tech

Stored XSS Flaws in Ninja Forms and WPC Product Bundles Plugins Exploited to Backdoor WordPress Sites

security-news technique

What Happened

According to BleepingComputer, attackers are actively exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins — Ninja Forms and WPC Product Bundles for WooCommerce — to install backdoors and create rogue administrator accounts on compromised sites. The report does not attribute either flaw to a specific CVE identifier, and no threat actor attribution is provided.

Why It Matters

Both plugins are widely deployed on WordPress sites for form building and e-commerce product bundling, respectively, making the potential attack surface broad. Stored XSS in a plugin's admin-facing input fields is a well-worn path to full site takeover: once injected script executes in an authenticated admin's browser session, attackers can leverage that session to create new admin users or drop a backdoor (e.g., a malicious plugin, theme file, or web shell) — effectively converting a client-side flaw into persistent server-side control. Site owners, agencies, and hosts running either plugin should treat this as an active, in-the-wild exploitation campaign rather than a theoretical risk.

What Defenders Should Watch For

  • Unexpected new WordPress administrator accounts, especially ones created outside normal onboarding workflows.
  • Unfamiliar or recently modified plugin/theme files, particularly around the time Ninja Forms or WPC Product Bundles form/product fields were last edited.
  • Stored content (form submissions, product bundle configuration fields) containing script tags, event handler attributes, or encoded payloads.
  • Outbound requests or cron-like behavior from the web server consistent with a backdoor checking in to a remote host.
  • As a mitigation, update both plugins to the latest vendor-patched versions, audit admin user lists, and review recent file changes on affected sites; where patches aren't yet available, consider disabling the affected input fields or taking the plugin offline until a fix is confirmed.

Developing Intel

This is a net-new report and details — including patch availability, affected version ranges, and a formal CVE assignment — may evolve. Defenders should track vendor advisories for both plugins directly. For the original reporting, see BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.