Skip to content
WordPress XSS Campaign Exploits Multiple Vulnerabilities

WordPress XSS Campaign Exploits Multiple Vulnerabilities

First seen 6 Oct 2026, 20:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 21:29 UTC
  • •Two critical XSS vulnerabilities in WordPress are being actively exploited.
  • •The attack installs a hidden admin account, compromising site security.
  • •WordPress version 7.1.3 released today addresses multiple vulnerabilities.

A recent campaign targets WordPress sites through stored Cross-Site Scripting (XSS) vulnerabilities, specifically CVE-2026-93836 in WPC Product Bundles for WooCommerce and CVE-2026-94504 in Ninja Forms. The attack employs a JavaScript payload that installs a hidden admin account, allowing unauthorized access and control over the site. The payload was first observed on October 4, 2026, and exploits vulnerabilities to execute malicious scripts in the browser of logged-in administrators. WordPress released version 7.1.3 on the same day, addressing several vulnerabilities, but did not confirm any of the flaws fixed in this update. The campaign highlights the need for immediate patching and vigilance among WordPress administrators to prevent unauthorized access.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
CVE-2026-87902 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-94504 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-93836 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-04
First exploitation attempt observed
Payload targeting CVE-2026-93836 in WPC Product Bundles was detected.
Patchstack
2026-10-05
Second exploitation attempt identified
The same payload was delivered through CVE-2026-94504 in Ninja Forms.
Patchstack
2026-10-06
WordPress version 7.1.3 released
The update patches seven vulnerabilities, including those exploited in the recent XSS campaign.
Cyberkendra

More articles in this cluster (3)

Following this threat?

Track CVE-2026-87902 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions of WordPress are affected?
The vulnerabilities affect versions of WPC Product Bundles for WooCommerce and Ninja Forms prior to their respective patches.
Is there evidence of active exploitation?
Yes, exploitation attempts have been confirmed against the identified vulnerabilities.
What should WordPress administrators do?
Administrators should update to WordPress version 7.1.3 immediately to mitigate the risks.