Attackers Exploit Two WordPress Plugins to Plant Backdoors and Admin Accounts

High · BleepingComputer ·

WordPress

Key points

  • Attackers are targeting Ninja Forms and WPC Product Bundles on WordPress sites.
  • Stored cross-site scripting is used to gain a foothold and compromise sites.
  • Intruders deploy backdoors and set up unauthorized administrator profiles.
  • No CVE identifiers are associated with this activity.
  • WooCommerce stores using affected plugins face elevated risk.

Attackers are targeting two widely used WordPress add-ons, Ninja Forms and WPC Product Bundles, by leveraging stored cross-site scripting weaknesses. The objective is to gain a foothold on sites, including those running WooCommerce. No CVE identifiers are currently associated with this activity, so standard vulnerability feeds may not provide timely warning.

Once a flaw is triggered, intruders can drop persistent access mechanisms and set up unauthorized administrator profiles. That combination gives them long-term control, allowing content changes, data theft, or further malware distribution. Site owners may not notice until visitors are redirected, SEO spam appears, or hosting providers flag suspicious activity.

Affected are WordPress site operators using these plugins, especially e-commerce stores relying on WooCommerce and WPC Product Bundles. Ninja Forms users are also at risk. Because the plugins are common, the potential pool is broad, though exploitation requires the vulnerable code to be present and reachable.

Why it matters: stored cross-site scripting can execute in privileged sessions, so an attacker may escalate from a low-level injection to full site compromise. Rogue admin accounts and backdoors are difficult to remove if not detected quickly. The lack of CVE tracking means defenders cannot rely on standard vulnerability feeds alone.

What to watch: plugin vendor advisories, unexpected admin users, unfamiliar scheduled tasks, modified theme or plugin files, and outbound connections. Review logs for suspicious POST requests or script injection attempts. Patch or disable affected plugins until fixes are confirmed.

What to do now

  1. Immediately update Ninja Forms and WPC Product Bundles to the latest patched versions; if no fix exists, deactivate or remove them.
  2. Audit WordPress users for unauthorized administrator or editor accounts, remove them, and rotate all privileged credentials and salts.
  3. Scan for backdoors by comparing core, plugin, and theme files against clean copies, and inspect uploads, mu-plugins, wp-config, cron jobs, and database options.
  4. Deploy WAF rules or virtual patching to block stored XSS patterns targeting these plugins.
  5. Review logs and isolate compromised sites; reset all admin passwords, enforce MFA, and apply least privilege.
  6. Notify hosting or security teams, preserve evidence, and rebuild from a clean backup if persistence is confirmed.
  7. Monitor vendor advisories and threat feeds for updates, since no CVE identifiers are currently available.

Original source

BleepingComputer

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news