Security researchers have uncovered an active campaign targeting WordPress websites. Attackers are abusing two stored cross-site scripting bugs in unrelated plugins. The goal is to plant backdoors and hidden administrator accounts on victim sites.
Patchstack researchers spotted the campaign in early October 2026. The two affected plugins are Ninja Forms and WPC Product Bundles for WooCommerce. Both receive the same JavaScript payload, which comes from the domain imgcdn1[.]com. The first infections appeared on October 4 and October 5.
Two high-severity flaws under attack
More than 500,000 people are currently using the plugin. The vulnerability relates to its historical submission editor that fails to ensure correct HTML encoding of input from a user. Hence, a perpetrator would be able to enter malicious code via the form field and the plugin would save it.
The second vulnerability is CVE-2026-93836. The vulnerability affects WPC Product Bundles for WooCommerce versions 8.6.6 and below. This plugin supports more than 30,000 online platforms. The vulnerability conceals itself within the parameter for ordering quantity. The attacker can enter a value beginning with a digit, though with malicious HTML code. The plugin accepts it and saves it as part of the order data.
Both bugs carry a CVSS score of 7.1, showing they are in the high-severity range. Moreover, attackers do not need to log in to inject the payload. They simply submit data through a public-facing form or checkout page.
The code then waits quietly inside a form submission or order record until an admin opens it. Patchstack notes that exploitation remains limited so far. Neither CVE appears in CISA’s Known Exploited Vulnerabilities catalog at the time of the report.
What the payload does once it fires
The script runs the moment an administrator views the poisoned submission or order. It then pulls a second-stage payload from the attacker-controlled domain. After that, the real damage begins.
The malware installs a bogus plugin known as ‘WP Smart Thumbnails.’ It acts as if it is a thumbnail management application. In actuality, however, it contains a backdoor. This makes it possible for the malware to set up two admin accounts – one of which is visible in the Users panel while the other remains completely hidden.
The concealment mechanism is quite ingenious. The malware introduces a so-called Must-Use plugin file that connects into all user queries in WordPress and prevents detection of the hidden account. Hence, even though the hidden admin is a registered user with all necessary privileges, it cannot display on the dashboard. In addition, site owners are never aware of the existence of the account, unless they search deeply into the database.
Furthermore, the perpetrators add another two backdoors: one is a secret login URL and the other is an anonymous file manager. The first one grants easy access to any malicious user who visits the link to become the oldest site admin.
The second one allows for the management of all files on the server. So, the person can read, upload, plus delete any file. The combination of these tools provides the attacker almost full control over the site.
Patching alone will not remove the infection
Both plugin makers have shipped fixes. Ninja Forms 3.15.4 & WPC Product Bundles 8.6.7 block the holes. By updating their software immediately, plugin owners can avoid further infections.
However, an update does not mean that the existing infection has been fixed. WordPress sites have faced other attacks that can lead to full site takeover, including the new WP2Shell attack tha lets hackers take over vulnerable WordPress websites.
Patchstack warns that even after removing the malicious plugin from the site, nothing changes in reality. The hidden admin and secret login survive because their code sits in the Must-Use plugins folder. Regular plugin removal tools cannot touch those files.
The malware also backdates its files. It scans the WordPress root directory, detects the relevant file within the root directory by spotting the earliest modified file, then it ends up copying this file into its own folder. Consequently, admins who monitor for recently modified files will not discover anything that is suspicious. Standard cleanup guides often rely on that method, so this trick defeats them.
What should site owners check right now?
Professionals advise administrators to review their accounts right away. The hidden account can’t be found in the dashboard. Site administrators should search the database for the administrator role and compare the results. Then, they should immediately investigate any unknown names.
Admins should also inspect the wp-content/mu-plugins/ directory. Legitimate Must-Use plugins are rare. Any unfamiliar file deserves close attention as attackers often mimic core file names to blend in.
If a site was hit, owners must reset passwords for every privileged account. They should also regenerate WordPress authentication salts. Patchstack recommends treating the oldest credentials of the admin as leaked, since the secret login backdoor operates as that user. Checking server logs for requests to imgcdn1[.]com can also reveal past infections.