Hackers are exploiting flaws in Ninja Forms and WPC Product Bundles to plant hidden administrator accounts on WordPress and WooCommerce sites, Patchstack reported October 6.
If your store or lead-capture site runs on WordPress, this is a full dashboard takeover that a plugin update does not undo. A Shopify storefront does not run these plugins. But plenty of high-ticket operators keep a WordPress blog, a quote-request site or a WooCommerce niche store next to the main store, and those are the sites in range. Your customer orders, form leads and admin logins all sit behind the account the attacker is after.
At Ecommerce Paradise I track the plugin and platform news that changes how you run a store, and this one comes with a cleanup list that most update notices skip. Below: what Patchstack found, why the patch is not the cure, where the risk really sits and a six-step check you can run this week. If you are still learning the model behind all of this, start with my guide to what high-ticket dropshipping is.
If a breach ever lands on your store, the LLC is what stands between the business and your personal assets, so form yours with Northwest Registered Agent, the best LLC formation service for ecommerce owners. Northwest charges the same renewal price you paid in year one with no upsell ladder, which the cheap formation mills cannot say. Form your LLC with Northwest →
Ninja Forms and WPC Product Bundles Flaws Are Being Exploited
Patchstack, a WordPress security firm, said in an October 6 write-up that it first saw exploitation on October 4 against CVE-2026-93836, a stored cross-site scripting (XSS) flaw in WPC Product Bundles for WooCommerce. On October 5 it saw the same payload used against CVE-2026-94504, a matching flaw in Ninja Forms.
WPC Product Bundles versions through 8.6.6 are affected, and 8.6.7 fixes the bug. Ninja Forms versions through 3.15.3 are affected, and 3.15.4 fixes it. Patchstack rates both flaws 7.1 on the CVSS severity scale. The Ninja Forms listing on WordPress.org shows more than 500,000 active installs when I checked October 9. The WPC Product Bundles listing shows more than 30,000.
Per Patchstack, the WPC flaw enters through a quantity parameter that gets stored in WooCommerce order metadata. The Ninja Forms flaw enters through form submissions sent to admin-ajax.php and displays in the legacy admin submission editor. Neither route requires an account. A stranger places an order or fills in a public form with a script hidden inside.
Nothing happens until a logged-in administrator opens that order or submission in wp-admin. Then the script runs inside the admin’s own browser session, collects WordPress security tokens and uses the built-in plugin installer to upload a fake plugin. The plugin is called WP Smart Thumbnails, version 1.2.4, credited to “MediaPress Labs.”
BleepingComputer reported the campaign the same day and quoted Patchstack on the hidden account: “It is a fully privileged administrator the site owner cannot see.” Patchstack’s advice on patching, also quoted there: “Updating the vulnerable plugin prevents further exploitation but does not clean an existing infection.”
How many sites were hit is unknown. Patchstack said exploitation in its telemetry is limited so far, and it called the two affected plugins a floor: “Two is what we have confirmed, not what we expect the final count to be.” Daily Security Review noted October 7 that neither Patchstack nor the plugin vendors have published a count of compromised sites.
Why Updating Ninja Forms Does Not Remove the Hidden Admin
The bugs are not new. Patchstack says both were publicly disclosed September 22, and the Ninja Forms changelog dates the 3.15.4 security release to September 21. Exploitation started about two weeks later. The attacker’s domain, imgcdn1.com, was registered October 1, pointed at Cloudflare nameservers October 2 and first used in an attack October 4, according to Patchstack.
The patch closes the front door. The implant is built to outlast it. One successful run gives the attacker four ways back in, per Patchstack’s breakdown.
First, a visible administrator account created through the normal user screen. Second, a hidden administrator with a random name pulled from about 50 harmless words such as support, updater, maintenance or backup, an @wordpress.org email address and a 16-character password. Third, a magic login link at wp-login.php that signs the holder in as the site’s oldest existing administrator, not the hidden one. Fourth, an unauthenticated file manager sitting inside the fake plugin.
The hidden account and the login link live in must-use plugins, a WordPress folder that loads on every request, never shows on the Plugins screen and is not removed when you delete a plugin. Patchstack says the installer stamps those files with the oldest modification date it can find, so sorting by “recently changed” will miss them. Four of the five attacking IP addresses it logged were Tor exit nodes, and Patchstack says blocking IPs is not a durable fix.
The counterpoint is scale. Exploitation is described as limited, the attack needs an administrator to open the poisoned order or submission, and both bugs had patches out before the first attack. I found no source disputing Patchstack’s account. The open question is how many sites were already behind on updates when the attacks began.
Today’s security coverage on the site follows one pattern. This morning I wrote about the ASOS breach through customer messaging platforms. At midday the topic was locking down your store domain after unauthorized certificates showed up. Attackers keep going through the tools around the store, not the store itself.
Hidden WordPress Admins Put Your Customer Data and Uptime at Risk
My read is that the risk is concentrated, not universal. Three situations cover almost everyone.
If you run neither Ninja Forms nor WPC Product Bundles, this campaign skips you. But Patchstack calls the operation plugin-agnostic: the attackers collect stored XSS bugs and reuse one implant. The next plugin on their list could be one you run. If you updated both plugins before October 4, you are probably clean, and the checks below take about ten minutes to confirm it. If you updated after October 4, or you are still behind, assume compromise until the checks come back empty. That last group is the only one that should treat this as an emergency.
Here is rough math, and it is hypothetical. A WooCommerce store doing $1.2 million a year books about $3,300 a day. Three days offline for a cleanup is roughly $9,900 in lost sales, and your ad spend keeps running while the site is down. On a high-ticket store averaging $2,500 an order, that is about four lost orders. The cleanup bill comes on top.
The data side is worse. Orders carry names, addresses and phone numbers. A hidden admin can read all of it, and breach notification rules vary by state. I am not a lawyer, so the FTC’s data breach response guide for business is the right place to start if a check turns something up.
There is a revenue angle too. A site that Google flags for malware can see Shopping disapprovals, which means the damage may show up in your sales before you notice the breach. That is my inference from how Google treats compromised sites, not something Patchstack reported.
Platform choice matters here. Shopify patches the platform itself, and Shopify apps carry their own risk, but nobody on a hosted platform is waiting on a plugin author to fix a form editor. On WooCommerce, patching is your job or your host’s job. My breakdown of what a free WooCommerce store really costs per year shows plugin and hosting costs, and security labor never appears on that sheet.
Hosting helps less than people think. A managed host such as Cloudways can watch the server, cache and backups. It cannot stop a stored XSS payload from running in your own browser session.
My web hosting security checklist covers what a host should handle. A second post on managed versus unmanaged hosting explains where the line sits.
The other lever is how many people hold admin rights. Every virtual assistant, freelancer and agency with an administrator login is another session an attacker can ride. If you hire support staff through OnlineJobs.ph, give them a Shop Manager or Editor role first and promote only when the job demands it.
Form plugins deserve a second look. A hosted tool keeps submissions in its own dashboard instead of your wp-admin editor, which removes the exact path this attack uses. I compared the options in my guide to WordPress lead capture tools for ecommerce sites. Once signups land in your email tool, my post on the email flows every store should have running shows where they go next.
If owning plugin patching is not how you want to spend your week, that is a big part of why my team builds done-for-you Shopify stores through the turnkey service. You get a store on a platform where the core is patched for you, and you keep your time for suppliers and ads.
A store held together by loose plugins is a stack problem, and a stack problem is easier to fix with someone looking over it. Want 1-on-1 coaching to tighten up your high-ticket store? Get the coaching details →
Clean Your Ninja Forms and WooCommerce Site in Six Steps
Run these six in order, and take a full backup before step one so you can roll back your own changes.
- Check your plugin versions on the Plugins screen. You need Ninja Forms 3.15.4 or later (WordPress.org lists 3.15.5 as current) and WPC Product Bundles 8.6.7 or later (current is 8.7.4). Update both, then test a form submission and a checkout.
- Look for the fake plugin and its helpers through your host’s file manager or SFTP. Open /wp-content/plugins/wp-smart-thumbnails/ and, inside /wp-content/mu-plugins/, a file named class-wp-token-validate.php and any file starting with class-wp-query- followed by eight characters. Read file contents, not dates. If your host will not give you file and log access, price out a managed plan, and Liquid Web is one to compare.
- Audit your administrators at the database level. Ask your developer or host to list every user holding the administrator capability straight from the database, then compare that list with the Users screen. The hidden account will not appear on that screen.
- Search your server logs for imgcdn1.com, /fz/x.js, /fz/c.php and any request to wp-login.php with a _wplogin parameter. Check the wp_options table for entries named fz_emer_done_v1 and fz_emer_login_tokens. A live login-token entry means a backdoor may be active right now.
- If anything matches, treat the site as compromised. Remove the unknown accounts, the fake plugin and the must-use files, delete both fz_emer options, then rotate every admin password and the WordPress authentication salts. Treat the oldest administrator’s password as burned, since the magic link signs in as that user. Patchstack warns that deleting the options alone is not enough, because a new token can be issued while the must-use files remain. Consider restoring a backup from before October 4 and paying a professional to verify it.
- Shrink the blast radius. Do your daily order and lead review from a Shop Manager account, which cannot install plugins by default, so a poisoned order has less to work with. That is my read, so test it on your own site. The WordPress hardening handbook covers DISALLOW_FILE_EDIT, and the related DISALLOW_FILE_MODS setting also blocks dashboard plugin installs and updates, so try it on a staging copy first. If you want a second set of eyes on your stack, book a call through my discovery page.
Frequently Asked Questions
Do I need to worry if I only run Shopify?
Not about these two plugins, because they are WordPress plugins. Check any WordPress blog or landing site you keep beside your Shopify store, since those still run plugins.
Is updating the plugins enough?
No. Patchstack says the update stops new attacks but does not remove an account, plugin or must-use file that is already installed. Run steps two through four above.
How do I know whether my site was hit?
Look for the wp-smart-thumbnails folder, the must-use files and the two fz_emer database entries, and compare database admins against the Users screen. A site is only clean when all four checks come back empty.
Should I stop using Ninja Forms?
Not because of this bug alone, since version 3.15.4 fixed it. If you want submissions out of wp-admin entirely, a hosted form tool such as HubSpot keeps them in its own dashboard. My list of form builder alternatives compared at renewal price covers WordPress-native options.
Can email tools replace my form plugin?
For signups, often yes. Klaviyo builds signup forms that feed straight into your email flows. Omnisend offers the same. For quote requests and contact forms you may still want a form plugin, patched and on a leash.
Will my host handle this for me?
Only part of it. Hosts watch servers, not what your admin browser does with a poisoned order. If you are weighing a move, SiteGround is another host to compare. My list of signs you need to switch web hosts helps you decide.
Do I have to tell customers if a hidden admin was on my site?
State rules differ and depend on what data was exposed, so talk to a lawyer. The FTC guide linked above walks through containing the breach and notifying the right parties. Card disputes can follow a breach, and I covered how to stop disputes before they cost you.
Where should a new store owner start?
Pick a niche before you pick plugins. Grab my free niches list. Then work through everything you need to launch a high-ticket dropshipping business.
You would rather spend this week on suppliers and ads than on malware cleanup. Want my team to scale the store you already have? See the scaling service →
Check your plugin versions before you do anything else today, then run the file and database checks while the logs are still fresh. If the checks come back clean, you spent twenty minutes. If they do not, you caught it early. Subscribe to the YouTube channel for daily breakdowns. More breaking news coming through the day.
Related Articles
If this was useful, these go deeper:
- Web Hosting Security Checklist: Protect Your Website in 2026
- Best Managed WordPress Hosting in 2026: Verified Fast, Secure, and Hands-Off
- Best WordPress Lead Capture Tools for Ecommerce Sites in 2026
- Your Payment Processor Is a Single Point of Failure: Build a Backup Plan Before You Need One
- High-Ticket Niches List: 150+ Best Dropshipping Niches for 2026

Trevor Fenner is an ecommerce entrepreneur and the founder of Ecommerce Paradise, a platform focused on helping entrepreneurs build and scale profitable high-ticket ecommerce and dropshipping businesses. With over a decade of hands-on experience, Trevor specializes in high-ticket dropshipping strategy, niche and product selection, supplier recruiting and onboarding, Google & Bing Shopping ads, ecommerce SEO, and systems-driven automation and scaling. Through Ecommerce Paradise, he provides free education via in-depth guides like How to Start High-Ticket Dropshipping, advanced training through the High-Ticket Dropshipping Masterclass, and fully done-for-you turnkey ecommerce services for entrepreneurs who want a faster, more hands-off path to growth. Trevor is known for emphasizing sustainable, real-world ecommerce models over hype-driven tactics, helping store owners build scalable, sellable, and location-independent brands.
Still deciding what to sell?
Grab the free list of 1,000+ niches that work for high-ticket dropshipping, sorted by category.
Free. Unsubscribe any time.
