Medium cybersecurity update: BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins. NetworkFix reviewed the available source material to summarize the security issue, its potential impact and the defensive actions administrators should prioritize.

What Happened

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said. BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins Reach out to get featured—contact us to send your exclusive story idea, research, hacks, or ask us a question or leave a comment/feedback!  Ravie Lakshmanan  Aug 11, 2026 Supply Chain Attack / Vulnerability Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component." Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] – 100,000+ active installs Live Copy Paste for Elementor – Cross Domain Copy Paste & Page Duplicator [live-copy-paste] – 6,000+ active installs Pixel Gallery Addons for Elementor – Easy Grid, Creative Gallery, Drag and Drop Grid, Custom Grid Layout, Portfolio Gallery [pixel-gallery] – N/A Prime Slider Addons for Elementor – Widgets, Templates & Elementor Addons [bdthemes-prime-slider-lite] – N/A Smart Admin Assistant – Dashboard and Site Enhancements [smart-admin-assistant] – N/A Ultimate Post Kit Addons for Elementor [ultimate-post-kit] – N/A Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor [ultimate-store-kit] – 6,000+ active installs Users visiting the listings for each of the aforementioned plugins on the WordPress plugins directory are displayed the message that they have been closed as of either August 7 or 8, 2026, and are not available for download pending a "full review." The issue, per the WordPress security company, is rooted in an internal component called Biggopti that's shipped along with the plugins. The system is designed to pull promotional banners from their API server and render them in the WordPress admin dashboard by fetching relevant JSON files from a DigitalOcean Spaces bucket. The library has been found vulnerable to a cross-site scripting (XSS) flaw in the JSON response parsing code via the "display_id" parameter from the Sigmative API due to insufficient client-side escaping. As a result, an attacker who can compromise the API can inject arbitrary web scripts in pages that get executed every time a user accesses those pages.

Technical Details

Because the script runs on every "wp-admin" page load, the injected code gets activated silently in the browser of any logged-in administrator. The vulnerability is rated 5.4 on the CVSS scoring system, indicating medium severity. The change is said to have been first introduced on March 1, 2026, in "bdthemes-prime-slider-lite" before being applied to others. The attack is notable because it's entirely driven via the API and requires no plugin updates or files to be modified on disk. "Rogue actors obtained write access to that bucket, replacing the legitimate JSON responses with crafted payloads to exploit that vulnerability," Wordfence said. "The XSS fires inside every logged-in admin's browser, silently, on every wp-admin page load. From there, the injected script creates rogue administrator accounts, uploads a web shell plugin, and phones home to a command-and-control (C2) server." The main payload is delivered to the plugins using the "api-data-all-records" API endpoint. A JavaScript file named "w2.js," the payload performs the following actions – Contacts the C2 server ("ia-cdn[.]com/fz/c") with the victim website's origin to fetch targeting instructions. The execution is aborted if the C2 server returns a "skip" or "done" status.

Security Impact

Organizations using the affected technology should treat the report according to its medium severity classification. Creates a new rogue administrator via the WordPress REST API. Downloads a fake plugin ZIP from the C2 server and installs it via the standard plugin upload form, resulting in the deployment of a PHP web shell ("emer-run.php"). An alternate payload ("x.js") found hosted on the plugin developer's infrastructure is served to victims using the "api-data-records" API endpoint. It's designed to generate "deterministic" administrative credentials that are mathematically derived from the victim website's hostname. "This algorithm produces predictable usernames (bd_ followed by a 6-character base36 hash) and passwords (Bd@26! followed by the hash and x), pairing them with an @wordpress.org email address," Wordfence said. "Because the credentials are deterministic, threat actors do not need to store compromised site lists centrally, and incident responders can compute the exact username and password to hunt for on suspected domains." The generated credentials are then leveraged to create a malicious administrator user, and the results of the attack are then exfiltrated back to the C2 server.

Recommended Actions

  • Identify whether the affected product, service or software is present in the environment.
  • Review the original vendor or research advisory and verify affected versions before making configuration changes.
  • Apply vendor-provided security updates or mitigations as soon as operationally practical.
  • Review relevant security logs and monitoring alerts for signs of suspicious activity associated with the reported issue.
  • Use the CVE identifiers, where available, to validate exposure through vulnerability-management and asset-inventory tools.

Security Details

  • Severity: Medium
  • Original source: The Hacker News

Why This Matters

Cybersecurity teams should use reports like this as an input to risk-based vulnerability and threat management rather than relying on headline severity alone. Exposure depends on whether the affected technology is deployed, reachable by an attacker and protected by compensating controls. Confirming asset ownership, affected versions and available vendor fixes helps teams prioritize remediation while avoiding unnecessary emergency changes.

Original Report

NetworkFix recommends reviewing the complete original report from The Hacker News for the authoritative technical context, affected versions, indicators and vendor-specific remediation details: Read the original report.