Ninja Forms plugin flaw exploited to hack WordPress sites

Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored XSS flaws in the WordPress plugins Ninja Forms and WPC Product Bundles for WooCommerce to deploy backdoors and create rogue administrator accounts. Patchstack says the attacks use a shared payload from imgcdn1[.]com and urges site owners to update to fixed versions and check for signs of compromise. #NinjaForms #WPCProductBundlesforWooCommerce #Patchstack #CVE202694504 #CVE202693836

Keypoints

  • Two stored XSS vulnerabilities are being exploited in WordPress plugins.
  • The affected plugins are Ninja Forms and WPC Product Bundles for WooCommerce.
  • The attacks use authenticated sessions to inject malicious JavaScript.
  • The payload installs a fake plugin and creates hidden administrator access.
  • Admins should update to Ninja Forms 3.15.4+ and WPC Product Bundles 8.6.7+.

Read More: https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/