WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH
Cybersecurity DEVELOPING

Ninja Forms plugin flaw exploited to hack WordPress sites

Padlock and key on a table in front of dark server racksAI illustration
WORLDTECH illustration · AI-generated (Canva)

What happened

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors (a hidden way into a system that bypasses its login) and create rogue admin accounts.

Sources & evidence