Stored XSS Vulnerabilities in Ninja Forms and WPC Product Bundles Exploited to Compromise WordPress Sites
Active exploitation reported; backdoor installation and rogue admin account creation observed

Key Takeaways
- Stored XSS vulnerabilities in Ninja Forms and WPC Product Bundles for WooCommerce are being actively exploited.
- Exploitation results in backdoor installation and the creation of rogue administrator accounts.
- Affected parties include WordPress site owners using the identified plugins.
- Patching and updating to the latest plugin versions is the primary recommended mitigation.
Related Security News
Chinese Threat Group TA419 Impersonates US Officials to Target AI Policy Experts
According to Dark Reading, a Chinese threat group identified as TA419 has been conducting a cyber espionage campaign by impersonating US officials. The group established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations. The operation aims to gain unauthorized access to AI policy expertise and sensitive information, potentially compromising research and policy development pipelines.




