← All stories
● Covered by 2 sources · 2 reportsMedium impact2 negative

BdThemes WordPress Plugins Removed After Supply Chain Attack Creates Rogue Admins

🔄 Updated 1d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • BdThemes infrastructure compromised, affecting WordPress plugins.
  • Attackers modified a remote JSON feed to create rogue admin accounts.
  • WordPress.org removed all BdThemes products for review.
  • Over 350,000 active installations potentially affected.
  • Attack exploited an XSS vulnerability in JSON response parsing.

Supply Chain Attack on BdThemes

BdThemes, a developer of premium WordPress web-design tools, experienced a supply chain compromise. A threat actor gained access to the company's upstream infrastructure and modified a remote JSON feed. This altered feed was then delivered to administrators' browsers, enabling the creation of unauthorized administrator accounts on WordPress sites.

Plugins Removed from WordPress.org

Following the discovery of the attack, the WordPress Plugins team removed all affected BdThemes products from WordPress.org. These plugins are no longer available for download, pending a full review. BdThemes advertises a portfolio with over 350,000 active installations, including its flagship free Element Pack plugin, which alone has over 100,000 active installations.

Method of Attack

The attackers "poisoned a static remote JSON data stream fetched by an administrative promotional banner component" after obtaining write access to the vendor's storage bucket. This method is notable because it did not involve modifying source code files within the official WordPress.org repository. Instead, it exploited a cross-site scripting (XSS) vulnerability in the JSON response parsing code within the plugin developer's implementation.

Affected Plugins

The compromise affects several BdThemes plugins. These include Element Pack Addons for Elementor, Live Copy Paste for Elementor, Pixel Gallery Addons for Elementor, Prime Slider Addons for Elementor, Smart Admin Assistant, and Ultimate Post Kit. The Element Pack Addons for Elementor plugin alone accounts for over 100,000 active installations.

Impact and Detection

WordPress security firm Defiant, through its Wordfence web application firewall (WAF), began detecting attacks related to this compromise on August 7. The incident highlights a method of attack that bypasses traditional source code modification detection, allowing for the injection of arbitrary web scripts into WordPress admin dashboards.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 15

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

BdThemes, a WordPress plugin vendor, experienced a supply chain compromise where attackers poisoned a static remote JSON data stream, leading to the temporary disabling of several of their plugins on WordPress.org. This incident is significant because it bypassed traditional source code modification detection and could allow attackers to inject arbitrary web scripts into WordPress admin dashboards.

A threat actor compromised BdThemes' infrastructure, modifying a remote JSON feed to create rogue WordPress admin accounts through an XSS vulnerability in the Biggop Library. This supply-chain attack led to the removal of all BdThemes products from WordPress.org pending review, affecting over 350,000 active installations.