Report
Ninja Forms and WPC Product Bundles flaws reportedly exploited to hack WordPress sites
BleepingComputer reports attackers are exploiting stored cross-site scripting flaws to install backdoors and create rogue admin accounts.
TLDR
BleepingComputer reports that hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins: Ninja Forms and WPC Product Bundles for WooCommerce. The reported attacks aim to install backdoors and create rogue admin accounts.
Combined views
2.7K
1 Source, first seen ago
8 likes2 comments2 saves1 reposts