Cyberkendra WordPress XSS Campaign Exploits Multiple Vulnerabilities
Article Content
- •Two critical XSS vulnerabilities in WordPress are being actively exploited.
- •The attack installs a hidden admin account, compromising site security.
- •WordPress version 7.1.3 released today addresses multiple vulnerabilities.
A recent campaign targets WordPress sites through stored Cross-Site Scripting (XSS) vulnerabilities, specifically CVE-2026-93836 in WPC Product Bundles for WooCommerce and CVE-2026-94504 in Ninja Forms. The attack employs a JavaScript payload that installs a hidden admin account, allowing unauthorized access and control over the site. The payload was first observed on October 4, 2026, and exploits vulnerabilities to execute malicious scripts in the browser of logged-in administrators. WordPress released version 7.1.3 on the same day, addressing several vulnerabilities, but did not confirm any of the flaws fixed in this update. The campaign highlights the need for immediate patching and vigilance among WordPress administrators to prevent unauthorized access.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-87902 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions of WordPress are affected?
Is there evidence of active exploitation?
What should WordPress administrators do?
Continue Reading
Critical Zero-Day Vulnerabilities in Citrix NetScaler Under Active Exploitation On September 26, 2026, security firm watchTowr reported two unpatched zero-day vulnerabilities in Citrix NetScaler ADC and Gateway appliances, allowing remote code execution (RCE) and actively exploited in the wild. Citrix has confirmed the existence of these vulnerabilities, tracked as CVE-2026-88771 and…