High 7.2
CVE-2026-94504
Exploitation of Ninja Forms and WPC Product Bundles Stored XSS Vulnerabilities (CVE-2026-94504, CVE-2026-93836)
Vendor / product: Ninja Forms, WPC Product Bundles for WooCommerce
Event date: 2026-10-04
Public PoC: Yes
First tracked by RiskWire: 2026-10-08
Sources & citations (7)
- WordPress「Ninja Forms」の脆弱性 CVE-2026-94504がサイバー攻撃に悪用 rocket-boys.co.jp · 2026-10-07
- Hackers Exploit WordPress Plugin Flaws to Create Rogue Admin Accounts archyde.com · 2026-10-07
- When Stored XSS Becomes Persistent Administrator Access expertinthecloud.co.za · 2026-10-07
- Ninja Forms and WPC Product Bundles XSS Flaws Exploited to Backdoor WordPress Sites mallory.ai · 2026-10-07
- Hackers Exploit Ninja Forms and WPC Product Bundles XSS Flaws to Plant Hidden WordPress Admins securityonline.info · 2026-10-08
- Falha no plugin Ninja Forms permite invadir sites WordPress sempreupdate.com.br · 2026-10-07
- WordPress Sitelerinde Ninja Forms Açığı Üzerinden Saldırılar Başladı cozumpark.com · 2026-10-07
References
See CVE-2026-94504 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →