
Published 8 October 2026
If your WordPress site uses Ninja Forms or WPC Product Bundles for WooCommerce, check the plugin versions now. A report published on 6 October 2026 says attackers are exploiting stored cross-site scripting (XSS) flaws in both plugins, with attempts to install a malicious plugin and create administrator accounts. Updating closes the known vulnerable versions, but it does not remove an infection that may already be present.
The reported issues affect Ninja Forms versions 3.15.3 and earlier, and WPC Product Bundles for WooCommerce versions 8.6.6 and earlier. The recommended fixed versions are Ninja Forms 3.15.4 or later and WPC Product Bundles 8.6.7 or later. Ninja Forms’ official plugin listing now shows version 3.15.5, released on 28 September, so check the current version offered in your own dashboard before updating.
What is happening, and why should site owners care?
Stored XSS means harmful script content is saved in a site and may run later when a person with access views the affected content. In the reported activity, malicious script was placed in WooCommerce order data or Ninja Forms submissions. When an administrator opened that content, the script could use the administrator’s active session to install a rogue plugin and create unauthorised administrator access.
This matters even if the flaw requires an authenticated session: a compromised or misused account with sufficient access can become the route to a broader site takeover. A contact form or order record may look like routine business data, but anyone reviewing submissions should treat unexpected links, text, or unfamiliar entries cautiously while checking and updating the site.
Check the affected plugins safely
- Record what is installed. In WordPress, open Plugins > Installed Plugins. Note whether either named plugin is present and record its displayed version. If you manage several client sites, check each installation rather than assuming updates were applied everywhere.
- Back up before changing production. Make sure you have a recent, restorable backup of both the site files and database. If the site handles orders or enquiries, consider a quiet maintenance window and avoid overwriting newer business data with an old backup.
- Update from the dashboard. Use the plugin’s normal update mechanism and install a version newer than the affected release. The WordPress.org listing for Ninja Forms documents 3.15.4 and later; the incident report identifies 8.6.7 or later as the fixed range for WPC Product Bundles. Confirm the version after the update completes.
- Test key customer journeys. Submit a test enquiry, verify that notification emails arrive, and check that the submission appears as expected. For WooCommerce, test a product page, add-to-cart flow and checkout using your usual safe test process. Check the front end and administrator screens for errors.
Look for signs of compromise, not just a successful update
Security researchers reported that attackers attempted to add a plugin disguised as “WP Smart Thumbnails” and create administrator accounts, including one designed to be concealed from the standard Users list. Those are indicators worth checking, not a complete forensic checklist; a clean-looking dashboard alone cannot prove a site is clean.
- Review Users for unfamiliar administrator accounts and confirm with your team who should have that role.
- Review installed plugins for anything you do not recognise, including plugins with suspicious names or unexpected files. Do not delete unfamiliar items before recording details if you may need an investigation.
- Look for unusual activity around form submissions, WooCommerce orders, administrator logins and plugin installations, especially from 4 October 2026 onwards.
- If you find an unknown admin, suspicious plugin or unexplained login, treat the site as potentially compromised. Ask a qualified WordPress security professional or your hosting provider to investigate; preserve relevant logs and backups.
Important: A plugin update prevents further exploitation of the vulnerable version, but it does not clean malicious accounts, files or persistence mechanisms already placed on a site.
Reduce the chance of a repeat incident
Keep WordPress core, themes and plugins maintained, and remove extensions that are no longer needed. Limit administrator access to people who need it, use individual accounts rather than shared logins, and protect those accounts with strong unique passwords and multi-factor authentication where available. Review who can view form submissions and order data, since administrator activity is part of the exposure path described in this incident.
Set a simple update routine: check security notices, apply updates promptly, and test important forms and checkout after changes. For agencies and resellers, keep a site-by-site inventory of plugin names and versions so that one overlooked client installation does not remain vulnerable. Hosting and migration assistance can help with the server-side parts of website operations, but plugin updates and access reviews remain important site-owner tasks.
HostCupid perspective
For Indian businesses, a website often collects enquiries and customer orders throughout the working day. A small, repeatable maintenance process is more useful than waiting for a visible outage: inventory plugins, back up, update, test the business journey, and investigate suspicious access separately. HostCupid is a Chennai-based provider of WordPress hosting, website services and migration assistance; whichever provider you use, ask how you can access backups and request help investigating a suspected compromise.
Today’s action: check for the affected plugin versions, update them to fixed releases, then review administrator accounts and recent activity. If anything looks unfamiliar, do not assume updating alone has resolved it.
Sources
- Ninja Forms plugin flaw exploited to hack WordPress sites · 2026-10-06
- Ninja Forms – WordPress plugin listing and changelog
