Cybersecurity DEVELOPING
Ninja Forms plugin flaw exploited to hack WordPress sites
First reported Source: BleepingComputerLast editorial activity
What happened
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors (a hidden way into a system that bypasses its login) and create rogue admin accounts.
Sources & evidence
- BleepingComputer Reporting source
Ninja Forms plugin flaw exploited to hack WordPress sites ↗
https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/