Vulnerabilities · InfosecFeed Brief

Ninja Forms plugin flaw exploited to hack WordPress sites

Vulnerabilities

What you need to know

Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]

Source transparency

This is an InfosecFeed curated brief based on reporting from BleepingComputer. InfosecFeed does not claim ownership of the original reporting.

Read the original report at BleepingComputer ↗