Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

Ninja Forms and WPC Product Bundles Flaws Are Under Attack: What Canadian WordPress Owners Must Do

What Happened

Patchstack researchers identified an attack campaign on October 4 against sites running WPC Product Bundles for WooCommerce. The same activity hit Ninja Forms the next day, according to BleepingComputer. The flaws are stored cross-site scripting bugs. CVE-2026-94504 affects Ninja Forms 3.15.3 and older. CVE-2026-93836 affects WPC Product Bundles 8.6.6 and older.

The attacker plants a script in WooCommerce order data or Ninja Forms submissions. It runs when a logged-in administrator views the content. The script installs a fake plugin named WP Smart Thumbnails and creates an administrator account. The attacker keeps four ways in: a visible admin, a hidden admin, a secret login URL, and an unauthenticated file manager. Removing the fake plugin does not end access.

Why This Matters for Canadian Organizations

Ninja Forms runs on more than 500,000 sites. Canadian small businesses, municipalities, clinics, and nonprofits use it for contact and intake forms. These forms accept input from anyone on the internet. An administrator who opens a poisoned submission hands the attacker a full session.

Form entries often hold names, phone numbers, and health or financial details. A site takeover is a breach of security safeguards under PIPEDA. Organizations in Quebec face Law 25 incident duties as well. Patchstack calls exploitation limited today. The campaign is new, and the public details give other attackers a template.

What to Do

Update Ninja Forms to 3.15.4 and WPC Product Bundles to 8.6.7 or later. An update alone does not clean an infected site. Review the administrator list for unknown accounts. Look in the plugin list for WP Smart Thumbnails from MediaPress Labs. Search form entries and orders for script tags. Block the domain imgcdn1[.]com. Reset admin passwords and end all active sessions. Compare site files against a clean backup. See our TechTalk coverage and daily briefs for more patch alerts.

Enjoy this article? Don’t forget to share.