Ninja Forms plugin flaw exploited to hack WordPress sites
Attackers are exploiting stored cross-site scripting vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce. The flaws are being used to install backdoors and create rogue administrator accounts, BleepingComputer reports.