BleepingComputer reports that hackers are actively exploiting stored cross-site scripting (XSS) vulnerabilities in two separate WordPress plugins: Ninja Forms and WPC Product Bundles for WooCommerce. The two plugins are unrelated, but both are being used in what appears to be a coordinated wave of attacks against WordPress sites.
According to the report, the attacks go beyond typical XSS abuse. Once the flaws are exploited, the attackers install backdoors and create rogue administrator accounts, giving them persistent control over the affected sites. Stored XSS is especially dangerous because the malicious script is saved on the server and can run whenever a page containing it is loaded.
WordPress site owners using either plugin should treat the report as a serious warning and check for signs of compromise. BleepingComputer does not indicate that the two vulnerabilities share a common root cause, but the simultaneous exploitation suggests that attackers are actively scanning for sites running these plugins.