WordPress Plugin Flaws Exploited To Plant Hidden Admin Accounts

A shared payload exploited XSS flaws in two plugins to plant hidden administrator accounts and backdoors that persist through updates and deletion.

Published on Oct 7, 2026
WordPress Plugin Flaws Exploited To Plant Hidden Admin Accounts

Attackers have exploited stored cross-site scripting (XSS) flaws in two unrelated WordPress plugins to deliver the same payload, leaving compromised sites with administrator access their owners cannot see.

In research published Oct. 6, 2026, Patchstack said it first saw the payload on Oct. 4 in an attempt on CVE-2026-93836 in WPC Product Bundles for WooCommerce, then a day later through CVE-2026-94504 in Ninja Forms.

WPC Product Bundles has more than 30,000 active installations and Ninja Forms more than 500,000, though Patchstack said exploitation volume remained limited in its telemetry.

No login was needed to plant the code. It was stored in WooCommerce order data or a Ninja Forms submission and ran when an administrator opened it, riding that administrator’s live session rather than stealing the session cookie.

Each plugin was hit with a different injection, but both of them pulled the same second-stage script from the attackers’ server, which Patchstack said tied the attempts to one campaign.

Once it ran, the script installed a malicious plugin posing as a thumbnail-caching tool and created a new administrator account. The plugin then added a second administrator hidden from the WordPress Users screen, a backdoor login link that signed the holder in as the site’s oldest administrator, and a file manager that required no authentication.

Updating Does Not Remove the Backdoors

The fixes are in WPC Product Bundles 8.6.7 and Ninja Forms 3.15.4, but Patchstack said updating, or even deleting the malicious plugin, does not remove the hidden administrator or the backdoor login. Must-use plugins keep them in place, loading on every request without ever appearing on the Plugins screen.

Because the hidden administrator cannot be seen in the dashboard, Patchstack advised listing administrators directly from the database and comparing the result with what wp-admin shows. It also warned that the implants were backdated to match the oldest files in the WordPress installation, so a search for recently changed files would miss them.

Patchstack said any site where the code ran in an administrator’s browser should be treated as potentially compromised. It recommended rotating privileged passwords and WordPress authentication salts, treating the oldest administrator’s password as exposed even though it was never directly stolen.

The domain serving the payload was registered on Oct. 1, about 10 days after both flaws were publicly disclosed on Sept. 22.

This field is for validation purposes and should be left unchanged.

FREE NEWSLETTER

Cyber Weekly

Get curated cybersecurity news, threats and insights delivered free every Thursday.

Written By Written By
Alessandro Mascellino
Alessandro Mascellino Cybersecurity Reporter

Alessandro Mascellino is a British-Italian freelance journalist specializing in technology and gaming. He has contributed to several publications, including Wired, The Independent, and Android Police. By day, he works as a journalist. By night, he co-manages a game studio that creates narrative games.