A targeted WordPress campaign is exploiting stored Cross-Site Scripting vulnerabilities, including CVE-2026-94504 and CVE-2026-93836, to compromise administrator sessions and establish persistent access to affected websites. The campaign has been observed leveraging vulnerabilities in WPC Product Bundles for WooCommerce and Ninja Forms to deliver a common JavaScript payload. Rather than functioning as a simple XSS exploit, the payload acts as a post-exploitation implant that abuses an authenticated administrator session to install a malicious plugin, create privileged accounts, establish hidden persistence mechanisms and communicate with attacker-controlled infrastructure.
The campaign delivers a JavaScript implant through stored XSS vulnerabilities affecting WPC Product Bundles for WooCommerce and Ninja Forms. The payload is hosted on attacker-controlled infrastructure and executes within the WordPress administrative origin when vulnerable content is viewed by an administrator. It uses legitimate WordPress administrative functionality and extracts CSRF nonces from privileged pages to install a malicious plugin without requiring a separate server-side vulnerability. The installed plugin masquerades as a thumbnail-related component and contains a packed file manager capable of listing uploading deleting renaming reading and writing files. A secondary script creates a privileged administrator account and uses must-use plugins to conceal the account from WordPress user listings. It also establishes a backdoor login URL capable of authenticating as an existing administrator and backdates malicious files to make them appear older. The implant communicates execution status to its command-and-control infrastructure and maintains several persistence mechanisms that can survive removal of the initially exploited plugin.[/subscribe_to_unlock_form]
A targeted WordPress campaign is exploiting stored Cross-Site Scripting vulnerabilities, including CVE-2026-94504 and CVE-2026-93836, to compromise administrator sessions and establish persistent access to affected websites. The campaign has been observed leveraging vulnerabilities in WPC Product Bundles for WooCommerce and Ninja Forms to deliver a common JavaScript payload. Rather than functioning as a simple XSS exploit, the payload acts as a post-exploitation implant that abuses an authenticated administrator session to install a malicious plugin, create privileged accounts, establish hidden persistence mechanisms and communicate with attacker-controlled infrastructure.
The campaign delivers a JavaScript implant through stored XSS vulnerabilities affecting WPC Product Bundles for WooCommerce and Ninja Forms. The payload is hosted on attacker-controlled infrastructure and executes within the WordPress administrative origin when vulnerable content is viewed by an administrator. It uses legitimate WordPress administrative functionality and extracts CSRF nonces from privileged pages to install a malicious plugin without requiring a separate server-side vulnerability. The installed plugin masquerades as a thumbnail-related component and contains a packed file manager capable of listing uploading deleting renaming reading and writing files. A secondary script creates a privileged administrator account and uses must-use plugins to conceal the account from WordPress user listings. It also establishes a backdoor login URL capable of authenticating as an existing administrator and backdates malicious files to make them appear older. The implant communicates execution status to its command-and-control infrastructure and maintains several persistence mechanisms that can survive removal of the initially exploited plugin.[emaillocker id="1283"]
It demonstrates how stored XSS vulnerabilities can serve as an initial access mechanism for broader WordPress compromise rather than simply enabling browser-based script execution. Successful exploitation can result in administrator-level persistence through malicious plugins hidden administrator accounts must-use plugins backdoor authentication mechanisms and an unauthenticated file manager. Organizations should patch the affected WordPress plugins remove unauthorized administrator accounts and must-use plugins inspect recently modified or suspicious PHP files and review web server logs for abnormal login and plugin activity. Any site where the payload executed within an administrator session should be treated as potentially compromised and privileged credentials authentication salts and other persistence mechanisms should be rotated or invalidated after remediation.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1190 | Exploit Public | Facing Application- |
| Execution | T1059.007 | Command and Scripting Interpreter | JavaScript |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Credential access | T1555.003 | Credentials from Password Stores | Credentials from Web Browsers |
| Collection | T1005 | Data from Local System | - |
| Command and control | T1071.001 | Application Layer Protocol | Web Protocols |
| Exfiltration | T1041 | Exfiltration Over C2 Channel | - |
The following reports contain further technical details:
[/emaillocker]