Threat advisory · Multiple

Attackers are using a Ninja Forms flaw to take over WordPress sites

Since Oct 5, 2026 attackers have used a Ninja Forms flaw to add hidden admins to WordPress sites. Update to 3.15.4 and check for unknown accounts.

Since October 5, 2026, attackers have been exploiting a flaw in Ninja Forms, a WordPress contact-form plugin used on more than 500,000 websites, to quietly add hidden administrator accounts. If your website uses Ninja Forms, update it to version 3.15.4 today, then check for administrator accounts you don’t recognize.

What happened

On October 6, 2026, BleepingComputer reported that attackers were exploiting a stored cross-site scripting (XSS) flaw in Ninja Forms, tracked as CVE-2026-94504. XSS means an attacker gets their own code to run inside someone else’s web browser, here, a site administrator’s.

Security firm Patchstack spotted the campaign on October 4, 2026, aimed at a different plugin, WPC Product Bundles for WooCommerce (CVE-2026-93836). It saw the same code used against Ninja Forms the next day, which links both to a single attacker.

According to Patchstack:

  • An anonymous visitor can plant malicious code through an ordinary form submission.
  • The code runs when a logged-in administrator opens that submission in the WordPress dashboard.
  • Using the administrator’s session, it installs a fake plugin called “WP Smart Thumbnails” and creates new administrator accounts.
  • The attacker ends up with four ways back in: a visible admin account, a hidden admin account that doesn’t appear on the Users screen, a secret login link that signs in as the site’s oldest administrator, and a file manager inside the fake plugin.
  • Removing the fake plugin does not remove the hidden account or the secret login link.

Patchstack describes the number of attacks so far as limited. It is not yet known how many sites have been compromised, who is behind the campaign, or whether any Canadian sites are among them.

Who is affected

Any WordPress website running Ninja Forms 3.15.3 or older. That includes a lot of small organizations: Ninja Forms often powers the “contact us”, booking and quote-request forms on clinic, law firm, contractor and not-for-profit websites.

Online stores running WPC Product Bundles for WooCommerce 8.6.6 or older, used on more than 30,000 sites, are affected by the same campaign.

What to do now

If your website uses Ninja Forms or WPC Product Bundles

  1. Update now. Ninja Forms to 3.15.4 or later; WPC Product Bundles for WooCommerce to 8.6.7 or later. This is the single most useful step, and it’s part of normal patch management.
  2. Check your administrator accounts. Look for any you don’t recognize. Patchstack notes suspicious accounts may use an @wordpress.org email address or routine-sounding names such as “support”, “updater” or “maintenance”.
  3. Look past the dashboard. Because one account is hidden, whoever manages your site should list administrators straight from the database and compare that with the Users screen.
  4. Check for the attacker’s files. Look for a wp-smart-thumbnails plugin folder and for files named class-wp-token-validate.php or class-wp-query- followed by eight characters in wp-content/mu-plugins/ (a folder of “must-use” plugins that load automatically).
  5. Check the website’s logs for requests containing _wplogin or wp-smart-thumbnails.php, and for traffic to the domain imgcdn1[.]com.

If you find signs of compromise

Patchstack recommends treating the whole site as compromised, not just removing the planted code. That means removing the unauthorized accounts and files, resetting administrator passwords (starting with the oldest administrator account), and refreshing WordPress’s security keys. If you’re not sure how, get help before you start, so evidence isn’t lost.

What this means for organizations in BC and Alberta

Ninja Forms keeps form submissions in the website’s database, and an attacker with administrator access to the site can reach them. If your forms collect names, contact details or anything more sensitive, a compromise may also be a privacy breach. Checking whether the attacker got in is how you find out.

If personal information was involved:

  • Organizations covered by PIPEDA (the Personal Information Protection and Electronic Documents Act, Canada’s federal private-sector privacy law): report to the Office of the Privacy Commissioner of Canada and notify affected people as soon as feasible when the breach creates a real risk of significant harm.
  • Alberta private organizations (Alberta PIPA, the Personal Information Protection Act): the same “real risk of significant harm” test applies. Notify Alberta’s Office of the Information and Privacy Commissioner and affected individuals without unreasonable delay.
  • BC private organizations (BC PIPA): there is currently no mandatory breach notification requirement, but BC’s Office of the Information and Privacy Commissioner recommends notifying voluntarily.

Clinics and other organizations in British Columbia and Alberta whose web forms collect health or financial details should also check any sector rules and cyber insurance terms that apply to them.

How happier IT helps

Websites are easy to forget once they’re live. If you’d like a hand checking whether yours is affected, or keeping track of what needs updating across your organization, that’s what our vulnerability management work is for. Not sure where you stand? Our free IT assessment is a calm, no-pressure place to start.

Sources

More from the feed

Other incidents we've written up.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.