Threat Advisory

WordPress XSS Flaw Hides Admin Account via Malicious Plugin Installation

Threat: Vulnerability/Malware
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A targeted WordPress campaign is exploiting stored Cross-Site Scripting vulnerabilities, including CVE-2026-94504 and CVE-2026-93836, to compromise administrator sessions and establish persistent access to affected websites. The campaign has been observed leveraging vulnerabilities in WPC Product Bundles for WooCommerce and Ninja Forms to deliver a common JavaScript payload. Rather than functioning as a simple XSS exploit, the payload acts as a post-exploitation implant that abuses an authenticated administrator session to install a malicious plugin, create privileged accounts, establish hidden persistence mechanisms and communicate with attacker-controlled infrastructure.

The campaign delivers a JavaScript implant through stored XSS vulnerabilities affecting WPC Product Bundles for WooCommerce and Ninja Forms. The payload is hosted on attacker-controlled infrastructure and executes within the WordPress administrative origin when vulnerable content is viewed by an administrator. It uses legitimate WordPress administrative functionality and extracts CSRF nonces from privileged pages to install a malicious plugin without requiring a separate server-side vulnerability. The installed plugin masquerades as a thumbnail-related component and contains a packed file manager capable of listing uploading deleting renaming reading and writing files. A secondary script creates a privileged administrator account and uses must-use plugins to conceal the account from WordPress user listings. It also establishes a backdoor login URL capable of authenticating as an existing administrator and backdates malicious files to make them appear older. The implant communicates execution status to its command-and-control infrastructure and maintains several persistence mechanisms that can survive removal of the initially exploited plugin.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A targeted WordPress campaign is exploiting stored Cross-Site Scripting vulnerabilities, including CVE-2026-94504 and CVE-2026-93836, to compromise administrator sessions and establish persistent access to affected websites. The campaign has been observed leveraging vulnerabilities in WPC Product Bundles for WooCommerce and Ninja Forms to deliver a common JavaScript payload. Rather than functioning as a simple XSS exploit, the payload acts as a post-exploitation implant that abuses an authenticated administrator session to install a malicious plugin, create privileged accounts, establish hidden persistence mechanisms and communicate with attacker-controlled infrastructure.

The campaign delivers a JavaScript implant through stored XSS vulnerabilities affecting WPC Product Bundles for WooCommerce and Ninja Forms. The payload is hosted on attacker-controlled infrastructure and executes within the WordPress administrative origin when vulnerable content is viewed by an administrator. It uses legitimate WordPress administrative functionality and extracts CSRF nonces from privileged pages to install a malicious plugin without requiring a separate server-side vulnerability. The installed plugin masquerades as a thumbnail-related component and contains a packed file manager capable of listing uploading deleting renaming reading and writing files. A secondary script creates a privileged administrator account and uses must-use plugins to conceal the account from WordPress user listings. It also establishes a backdoor login URL capable of authenticating as an existing administrator and backdates malicious files to make them appear older. The implant communicates execution status to its command-and-control infrastructure and maintains several persistence mechanisms that can survive removal of the initially exploited plugin.[emaillocker id="1283"]

It demonstrates how stored XSS vulnerabilities can serve as an initial access mechanism for broader WordPress compromise rather than simply enabling browser-based script execution. Successful exploitation can result in administrator-level persistence through malicious plugins hidden administrator accounts must-use plugins backdoor authentication mechanisms and an unauthenticated file manager. Organizations should patch the affected WordPress plugins remove unauthorized administrator accounts and must-use plugins inspect recently modified or suspicious PHP files and review web server logs for abnormal login and plugin activity. Any site where the payload executed within an administrator session should be treated as potentially compromised and privileged credentials authentication salts and other persistence mechanisms should be rotated or invalidated after remediation.

RECOMMENDATIONS:

  • We recommend you to update Ninja Forms to version 3.15.4 or later.
  • We recommend you to update WPC Product Bundles for WooCommerce to version 8.6.7 or later.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1190 Exploit Public Facing Application-
Execution T1059.007 Command and Scripting Interpreter JavaScript
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols
Exfiltration T1041 Exfiltration Over C2 Channel -

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu