MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-10-06 · via BleepingComputer

WordPress Plugin Vulnerabilities Weaponized to Establish Backdoor Access

Image via BleepingComputer
Image via BleepingComputer

Attackers are actively exploiting stored cross-site scripting flaws in the Ninja Forms and WPC Product Bundles for WooCommerce plugins to inject malicious code into WordPress administrator sessions. Once triggered, the attack installs a disguised malicious plugin and creates hidden administrative accounts while establishing multiple persistence mechanisms that remain functional even after the plugin removal. The Ninja Forms plugin alone affects over 500,000 WordPress installations, making this campaign a widespread threat to website operators.

Expanded Detail

The exploitation technique relies on injecting malicious scripts into legitimate plugin data repositories. When site administrators access stored information—such as WooCommerce orders or form submissions—the hidden code activates within their authenticated browser session, granting the attacker the same privileges as the administrator without requiring separate login credentials.

The threat actors have implemented multiple redundant access points designed to persist even after cleanup attempts. By creating hidden user accounts and alternate login mechanisms through separate backdoor plugins with falsified installation dates, attackers can maintain access to compromised sites long after the original vulnerable plugin is patched or removed.

Context

This campaign affects hundreds of thousands of WordPress installations globally, potentially impacting e-commerce sites, contact forms, and data collection systems. Site owners may face data theft, payment processing compromise, or unauthorized modifications to their platforms. The attack's reliance on administrator session hijacking means attackers could access sensitive business information and customer data. Organizations using these plugins face significant remediation costs, and widespread compromise could erode trust in WordPress plugin ecosystems, affecting the estimated millions of small businesses relying on these platforms.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Critical Rejetto File Server Vulnerability Under Active Exploitation for Unauthorized Access · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Ninja Forms plugin flaw exploited to hack WordPress sites.” Browse more stories.