Security News Ninja Forms plugin flaw exploited to hack WordPress sites BleepingComputer Daniel Bender 06 Oct 2026 Share Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts.