Skip to main content
CyberReportedMediumDeveloping
5.0

WordPress plugins Ninja Forms, WPC Product Bundles exploited for backdoors

Threat actors are actively exploiting stored XSS vulnerabilities in Ninja Forms and WPC Product Bundles for WooCommerce to install backdoors and create rogue admin accounts on WordPress sites. The attacks target unpatched installations, and the full scope of compromise is still being assessed. This highlights the persistent risk of plugin vulnerabilities in the WordPress ecosystem.

BleepingComputer2 days agoengCredibility 16%View source

Score Breakdown

Mosaic Score5.0
Model confidence0.7
Significance0.5
Source credibility0.2
Source

Related signals

2 found