BdThemes, a developer of premium WordPress web-design tools, experienced a supply chain compromise. A threat actor gained access to the company's upstream infrastructure and modified a remote JSON feed. This altered feed was then delivered to administrators' browsers, enabling the creation of unauthorized administrator accounts on WordPress sites.
Following the discovery of the attack, the WordPress Plugins team removed all affected BdThemes products from WordPress.org. These plugins are no longer available for download, pending a full review. BdThemes advertises a portfolio with over 350,000 active installations, including its flagship free Element Pack plugin, which alone has over 100,000 active installations.
The attackers "poisoned a static remote JSON data stream fetched by an administrative promotional banner component" after obtaining write access to the vendor's storage bucket. This method is notable because it did not involve modifying source code files within the official WordPress.org repository. Instead, it exploited a cross-site scripting (XSS) vulnerability in the JSON response parsing code within the plugin developer's implementation.
The compromise affects several BdThemes plugins. These include Element Pack Addons for Elementor, Live Copy Paste for Elementor, Pixel Gallery Addons for Elementor, Prime Slider Addons for Elementor, Smart Admin Assistant, and Ultimate Post Kit. The Element Pack Addons for Elementor plugin alone accounts for over 100,000 active installations.
WordPress security firm Defiant, through its Wordfence web application firewall (WAF), began detecting attacks related to this compromise on August 7. The incident highlights a method of attack that bypasses traditional source code modification detection, allowing for the injection of arbitrary web scripts into WordPress admin dashboards.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
BdThemes, a WordPress plugin vendor, experienced a supply chain compromise where attackers poisoned a static remote JSON data stream, leading to the temporary disabling of several of their plugins on WordPress.org. This incident is significant because it bypassed traditional source code modification detection and could allow attackers to inject arbitrary web scripts into WordPress admin dashboards.
A threat actor compromised BdThemes' infrastructure, modifying a remote JSON feed to create rogue WordPress admin accounts through an XSS vulnerability in the Biggop Library. This supply-chain attack led to the removal of all BdThemes products from WordPress.org pending review, affecting over 350,000 active installations.