Hackers Exploit XSS Flaws in Popular WordPress Plugins to Plant Backdoors
Security researchers have uncovered a coordinated campaign in which attackers abuse stored cross‑site scripting (XSS) weaknesses in two widely used WordPress extensions – Ninja Forms and WPC Product Bundles for WooCommerce – to inject malicious code, install backdoors and silently create unauthorized administrator accounts.
Stored XSS vulnerabilities allow hostile scripts to be saved on a server and later executed in the browser of any user who views the compromised page. In the case of WordPress plugins, the flaw typically resides in input fields that fail to properly sanitise user‑supplied data before persisting it to the database. When an administrator later accesses the affected interface, the hidden script runs with their privileges.
The two compromised extensions serve very different purposes. Ninja Forms is a drag‑and‑drop form builder employed by thousands of sites to collect contact information, while WPC Product Bundles for WooCommerce enables merchants to sell grouped products as a single offering. Despite serving distinct niches, both plugins were found to contain similar XSS entry points that attackers could weaponise without requiring any prior authentication.
Exploitation proceeds by injecting a payload that, once triggered, downloads and executes a secondary script. That script establishes a persistent backdoor, often by creating a new user with administrator rights, granting the attacker full control over the compromised WordPress installation. Because the malicious code is stored on the site itself, it can survive routine updates and remain hidden from casual inspection.
WordPress powers roughly 40 % of all websites on the internet, and its extensibility through third‑party plugins is both a strength and a security challenge. When a site is commandeered in this manner, attackers can repurpose it for spam distribution, phishing campaigns, or as a foothold for further network intrusion, amplifying the risk far beyond the initial breach.
Both plugin authors have responded by releasing patches that neutralise the vulnerable input vectors and by urging users to update immediately. The WordPress security team has also issued advisories recommending that administrators verify they are running the latest versions, review user accounts for unexpected administrators, and employ security plugins that can detect anomalous behaviour.
The incident underscores a broader concern within the WordPress ecosystem: the sheer volume of plugins makes comprehensive code review difficult, and many site owners rely on extensions that receive infrequent updates. Regular vulnerability scanning, timely application of patches, and limiting the number of active plugins are widely accepted best practices to mitigate such threats.
Going forward, security researchers expect the disclosed flaws to be assigned CVE identifiers and to be tracked in vulnerability databases. Site owners are advised to monitor official channels for further guidance, consider implementing a web‑application firewall, and maintain routine backups to ensure rapid recovery if a compromise does occur.
Comments (0)
Be the first to comment.
Join the discussion