Last updated: October 7, 2026 at 2:03 PM UTC
All 903 Vulnerability 367 Breach 144 Threat 385 Defense 7
Tag: patchstack (1 article)Clear

Attackers exploit Ninja Forms WordPress plugin stored cross-site scripting flaw to plant site backdoors

Patchstack identified a campaign on October 4 exploiting CVE-2026-94504, a high-severity stored cross-site scripting flaw in the Ninja Forms WordPress plugin, which is installed on more than 500,000 sites. Attackers plant malicious JavaScript in form submissions, and when a logged-in administrator loads the content, the script runs under the authenticated WordPress session. The payload installs a backdoor plugin and creates several hidden access paths: a visible administrator account, a concealed account kept out of the user list, a secret login URL, and unauthenticated file manager access. Versions 3.15.3 and older are affected, with a fix in 3.15.4.

Check
Update the Ninja Forms plugin to 3.15.4 or later on all WordPress sites, then check for unknown administrator accounts, rogue plugins, and hidden login paths.
Affected
WordPress sites running Ninja Forms 3.15.3 or older let attackers store malicious JavaScript that runs in an administrator's session to install backdoors and hidden admin accounts.
Fix
Upgrade Ninja Forms, remove unauthorized admin accounts and backdoor plugins, rotate credentials and keys, and audit for secret login URLs and file manager access.