Exploited WordPress plugin flaws accompany core 7.1.3 fixes
Attackers exploit stored XSS in two WordPress plugins and a critical Bricksforge upload flaw, while core 7.1.3 patches seven separate issues.
Patchstack and BleepingComputer describe active but currently limited exploitation of two unrelated stored XSS flaws that load the same JavaScript from imgcdn1.com and then use an administrator session. CVE-2026-93836 affects WPC Product Bundles for WooCommerce through 8.6.6 (about 30,000 installs per Patchstack, more than 30,000 sites per BleepingComputer, CVSS 7.1), first seen October 4, 2026, and CVE-2026-94504 affects Ninja Forms through 3.15.3 (about 500,000 versus more than 500,000, CVSS 7.1), with Patchstack dating that payload to October 5 while BleepingComputer dates the shared script to October 4. The payload installs a plugin that BleepingComputer names WP Smart Thumbnails, creates a hidden administrator and secret login, exposes an unauthenticated file manager, backdates files, and reports to attacker infrastructure; updating to Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7 or later stops new exploitation but does not remove infections. Separately, WordPress 7.1.3, released October 6, 2026, ships seven security fixes and four bug fixes, including comments stored XSS in 7.1.0–7.1.2, WXR second-order SQL injection, denial of service in WP_Http::make_absolute_url(), Author sticky-post abuse, unauthenticated disclosure of comments on private and unpublished posts, Imgur oEmbed XSS, and forgeable hook parameters, and no source links it to the plugin campaign. WordPress.org says fixes are backported through 4.7 and, with Cyber Security News, urges an immediate update, while Patchstack says backports go through 6.6, calls the release not an emergency, and adds that 7.1.2 fixed CVE-2026-87902 (unauthenticated local file inclusion that could lead to remote code execution), with branches 4.7–6.5 not yet patched and cached Imgur embeds remaining until caches are cleared. On October 8 Patchstack reported active exploitation, first seen October 7, of CVE-2026-85097, a CVSS 10.0 unauthenticated arbitrary file upload in Bricksforge through 3.1.8.9 (fixed in 3.1.8.10) that can place PHP files and enable remote code execution, with telemetry from 63 source IPs.
- CVE-2026-93836 affects WPC Product Bundles for WooCommerce through 8.6.6 (about 30,000 installs per Patchstack; more than 30,000 sites per BleepingComputer; CVSS 7.1), with exploitation first seen October 4, 2026.
- CVE-2026-94504 affects Ninja Forms through 3.15.3 (about 500,000 installs per Patchstack; more than 500,000 per BleepingComputer; CVSS 7.1); 3.15.4 strengthens output escaping. Patchstack dates that payload to October 5, while…
Coverage timelineoldest first · each row is one article
- · 2d agoFour ways back in: the WordPress XSS campaign that hides its own admin account
Patchstack· 76
Attackers are exploiting stored XSS in two WordPress plugins to install hidden admin backdoors.
- · 2d agoWordPress 7.1.3 Maintenance and Security Release
WordPress.org · Security· 60
WordPress 7.1.3 fixes seven vulnerabilities, including stored XSS, SQL injection, and unauthenticated disclosure of private comments.
- · 2d agoWordPress 7.1.3 Security Release
Patchstack· 64
WordPress 7.1.3 patches seven flaws, including unauthenticated comment leaks and stored XSS, and is not an emergency.
Vulnerabilities in this storyAll →
- CVE-2026-850979.8—Unauthenticated file upload to RCE in WordPress Bricksforgepublished · Bricksforge
- CVE-2026-879028.140%Unauthenticated Local File Inclusion to RCE in WordPress Core (fixed in 7.1.2)published · WordPress (WordPress.org) WordPress core