Back to all news
Security

Ninja Forms plugin flaw exploited to hack WordPress sites

BleepingComputer·October 6, 2026·1 min read
Ninja Forms plugin flaw exploited to hack WordPress sites

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. The attacks allow full site compromise, enabling attackers to steal data, inject malicious content, or use the site for further campaigns.

Read at BleepingComputer
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store