CyberNotableReported
5.1
ClingSTUN Backdoor Turns IoT Devices into Proxy Nodes via STUN
Dark ReadingLO·3 days ago
Threat actors are actively exploiting stored XSS vulnerabilities in Ninja Forms and WPC Product Bundles for WooCommerce to install backdoors and create rogue admin accounts on WordPress sites. The attacks target unpatched installations, and the full scope of compromise is still being assessed. This highlights the persistent risk of plugin vulnerabilities in the WordPress ecosystem.