Patchstack identified a campaign on October 4 exploiting CVE-2026-94504, a high-severity stored cross-site scripting flaw in the Ninja Forms WordPress plugin, which is installed on more than 500,000 sites. Attackers plant malicious JavaScript in form submissions, and when a logged-in administrator loads the content, the script runs under the authenticated WordPress session. The payload installs a backdoor plugin and creates several hidden access paths: a visible administrator account, a concealed account kept out of the user list, a secret login URL, and unauthenticated file manager access. Versions 3.15.3 and older are affected, with a fix in 3.15.4.