BdThemes supply-chain attack creates rogue WordPress admins, hits 100,000 sites

BdThemes supply-chain attack creates rogue WordPress admins, hits 100,000 sites

Attackers breached the infrastructure of BdThemes, a developer of premium WordPress plugins, and used a modified remote JSON feed to create rogue administrator accounts on victims' sites. The incident affected the company's flagship free plugin Element Pack, which has over 100,000 active installations on WordPress.org, while the developer's entire portfolio exceeds 350,000 active installs.

Starting Saturday, all BdThemes products were closed for download by the WordPress Plugins team, which is conducting a full code review. The attack began on August 7, when researchers at Defiant, the company behind the Wordfence security plugin, detected suspicious activity through their web application firewall.

The researchers found that the attacker gained write access to the vendor's cloud storage and "poisoned" a static remote JSON stream used by an administrative promotional banner component. The code responsible for parsing JSON responses contained a cross-site scripting (XSS) vulnerability introduced in March 2026. This allowed the attacker to replace legitimate promotional data with malicious code exploiting the flaw.

The issue resides in the Biggop Library, part of the Biggopti component that fetches promotional banners from the vendor's API server and displays them in the WordPress admin dashboard. The malicious JavaScript used an authenticated session of a legitimate administrator to create fake accounts with admin rights. An additional payload in the form of w2.js established persistence through a webshell named emer-run.php, disguised as an installed plugin.

According to Wordfence, the vulnerability stems from insufficient output escaping in the display_id parameter from the Sigmative API. This allows an attacker who compromises the Sigmative API server to inject arbitrary web scripts into pages, which execute whenever a user visits them. The issue received a "medium" severity rating, and as of Defiant's report, it remained unpatched.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate