Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
What happened
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
Why it matters
The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.
Affected entities
View evidence
1 reports · 1 original report · 1 independent
- BleepingComputerPrimary source · Supports · EN · 100%Ninja Forms plugin flaw exploited to hack WordPress sites ↗
Claims
- Ninja Forms plugin flaw exploited to hack WordPress sites Observed
Conflicts
No material conflict detected in the available evidence.
Timeline
- First reported
Market move following event
Market reaction is not yet available for this asset and time window.
Score explanation
Confidence · formula confidence-2.1.0
Source trust84
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude96
Market relevance74
Entity significance42
Market breadth45
Novelty68
Urgency96
Ranking · formula rank-1.0.0
Confidence factor0.847
Freshness factor0.9997
Breaking bonus8