RW
RiskWire Real-time vulnerability intelligence
This week Pricing Live dashboard
High 7.2

CVE-2026-94504

Exploitation of Ninja Forms and WPC Product Bundles Stored XSS Vulnerabilities (CVE-2026-94504, CVE-2026-93836)

Vendor / product: Ninja Forms, WPC Product Bundles for WooCommerce
Event date: 2026-10-04
Public PoC: Yes
First tracked by RiskWire: 2026-10-08

Sources & citations (7)

References

See CVE-2026-94504 in context

RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.

Book a 20-min demo →