Published 8 October 2026

If your WordPress site uses Ninja Forms or WPC Product Bundles for WooCommerce, check the plugin versions now. A report published on 6 October 2026 says attackers are exploiting stored cross-site scripting (XSS) flaws in both plugins, with attempts to install a malicious plugin and create administrator accounts. Updating closes the known vulnerable versions, but it does not remove an infection that may already be present.

The reported issues affect Ninja Forms versions 3.15.3 and earlier, and WPC Product Bundles for WooCommerce versions 8.6.6 and earlier. The recommended fixed versions are Ninja Forms 3.15.4 or later and WPC Product Bundles 8.6.7 or later. Ninja Forms’ official plugin listing now shows version 3.15.5, released on 28 September, so check the current version offered in your own dashboard before updating.

What is happening, and why should site owners care?

Stored XSS means harmful script content is saved in a site and may run later when a person with access views the affected content. In the reported activity, malicious script was placed in WooCommerce order data or Ninja Forms submissions. When an administrator opened that content, the script could use the administrator’s active session to install a rogue plugin and create unauthorised administrator access.

This matters even if the flaw requires an authenticated session: a compromised or misused account with sufficient access can become the route to a broader site takeover. A contact form or order record may look like routine business data, but anyone reviewing submissions should treat unexpected links, text, or unfamiliar entries cautiously while checking and updating the site.

Check the affected plugins safely

  1. Record what is installed. In WordPress, open Plugins > Installed Plugins. Note whether either named plugin is present and record its displayed version. If you manage several client sites, check each installation rather than assuming updates were applied everywhere.
  2. Back up before changing production. Make sure you have a recent, restorable backup of both the site files and database. If the site handles orders or enquiries, consider a quiet maintenance window and avoid overwriting newer business data with an old backup.
  3. Update from the dashboard. Use the plugin’s normal update mechanism and install a version newer than the affected release. The WordPress.org listing for Ninja Forms documents 3.15.4 and later; the incident report identifies 8.6.7 or later as the fixed range for WPC Product Bundles. Confirm the version after the update completes.
  4. Test key customer journeys. Submit a test enquiry, verify that notification emails arrive, and check that the submission appears as expected. For WooCommerce, test a product page, add-to-cart flow and checkout using your usual safe test process. Check the front end and administrator screens for errors.

Look for signs of compromise, not just a successful update

Security researchers reported that attackers attempted to add a plugin disguised as “WP Smart Thumbnails” and create administrator accounts, including one designed to be concealed from the standard Users list. Those are indicators worth checking, not a complete forensic checklist; a clean-looking dashboard alone cannot prove a site is clean.

Important: A plugin update prevents further exploitation of the vulnerable version, but it does not clean malicious accounts, files or persistence mechanisms already placed on a site.

Reduce the chance of a repeat incident

Keep WordPress core, themes and plugins maintained, and remove extensions that are no longer needed. Limit administrator access to people who need it, use individual accounts rather than shared logins, and protect those accounts with strong unique passwords and multi-factor authentication where available. Review who can view form submissions and order data, since administrator activity is part of the exposure path described in this incident.

Set a simple update routine: check security notices, apply updates promptly, and test important forms and checkout after changes. For agencies and resellers, keep a site-by-site inventory of plugin names and versions so that one overlooked client installation does not remain vulnerable. Hosting and migration assistance can help with the server-side parts of website operations, but plugin updates and access reviews remain important site-owner tasks.

HostCupid perspective

For Indian businesses, a website often collects enquiries and customer orders throughout the working day. A small, repeatable maintenance process is more useful than waiting for a visible outage: inventory plugins, back up, update, test the business journey, and investigate suspicious access separately. HostCupid is a Chennai-based provider of WordPress hosting, website services and migration assistance; whichever provider you use, ask how you can access backups and request help investigating a suspected compromise.

Today’s action: check for the affected plugin versions, update them to fixed releases, then review administrator accounts and recent activity. If anything looks unfamiliar, do not assume updating alone has resolved it.


Sources

Portrait of Ananya Krishnan, HostCupid editorial persona
Published by
Ananya Krishnan

HostCupid Editorial Team

Writes practical guides on web hosting, WordPress, website migrations and day-to-day website operations for Indian businesses.

Editorial persona representing the HostCupid content team.

← More HostCupid Insights