WordPress plugin attacks create hidden administrator access

WordPress plugin attacks create hidden administrator access. Attackers are exploiting flaws in two WordPress plugins to install backdoors and create hidden administrator access.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Wednesday, October 7th, 2026.

Attackers are exploiting flaws in two WordPress plugins to install backdoors and create hidden administrator access. Ninja Forms is installed on more than five hundred thousand sites, while WPC Product Bundles for WooCommerce is active on more than thirty thousand. The attack plants malicious JavaScript in a form submission or order. When a logged-in administrator views that content, the script can run through the administrator’s authenticated session. Reported exploitation is currently limited, but applying an update doesn’t remove an infection that is already present.

That cleanup warning matters because compromised sites can retain hidden accounts and secret login routes even after the visible malicious plugin is deleted. For leaders, websites handling customer forms or commerce may remain exposed after routine patching. For defenders, update both plugins, inspect administrator accounts and investigate the documented persistence mechanisms. Review suspicious submissions, orders and recently installed plugins as part of that work.

The larger lesson is that prevention and incident cleanup are separate jobs. Patch the affected plugins, then perform a compromise review instead of assuming the update cleaned the site.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

WordPress plugin attacks create hidden administrator access
Broadcast by