> Ninja Forms plugin flaw exploited to hack WordPress sites
[AUTHOR: Bill Toulas]
[DATE: 06/10/2026 21:00]
[LANGUAGE: EN]
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]