TechNewsReel
Live

BdThemes Supply Chain Attack Poisons API to Create Rogue WordPress Admins

Attackers bypassed file-integrity monitoring by poisoning remote JSON streams to hijack administrative accounts.

TechNewsReel Newsroom · August 11, 2026

A sophisticated supply chain attack targeting WordPress plugin vendor BdThemes has allowed hackers to create rogue administrator accounts and install persistent webshells across thousands of websites. The breach was detected by Wordfence and Defiant researchers on August 7, 2026, revealing a stealthy method of compromise that avoids modifying official source code.

According to security researchers, the attackers compromised BdThemes' upstream infrastructure to poison a remote JSON data stream used for administrative promotional banners. By exploiting a cross-site scripting (XSS) vulnerability in the JSON parsing code of the Biggop Library—specifically within the Biggopti component—the attackers executed malicious JavaScript in the browsers of logged-in administrators. This API-driven approach enabled the creation of rogue admin accounts and the deployment of a webshell named "emer-run.php" via a fake plugin identified as "w2.js."

A New Vector for Compromise

The vulnerability that facilitated the attack was introduced into the Biggop Library in March 2026. Unlike traditional supply chain hacks that involve injecting malicious code into a software update or a repository, this attack occurred entirely via external API responses. Because the official files hosted on the WordPress.org repository remained untouched, the breach was invisible to standard file-integrity monitoring tools.

Paolo Tresso, a researcher at Wordfence, noted that "unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository." To further evade detection, the attackers used database query manipulation to hide the rogue administrator accounts from the standard WordPress user list.

Industry Implications

This incident marks a dangerous evolution in supply chain threats, shifting the point of failure from the software package to the external data streams the software trusts. BdThemes maintains a significant footprint in the WordPress ecosystem, with a portfolio including Element Pack, Prime Slider, and Ultimate Post Kit, totaling over 350,000 active installations. The ability to compromise such a large user base without triggering file-change alerts demonstrates a high level of stealth and technical precision.

Furthermore, the command-and-control (C2) infrastructure used in this campaign has been linked to the same threat actor responsible for previous supply-chain compromises involving OptinMonster and the Advanced Responsive Video Embedder, suggesting a persistent and experienced adversary targeting the WordPress ecosystem.

Current Status

Following notification of the breach on August 7, 2026, the WordPress Plugins team temporarily disabled all affected BdThemes plugins pending a comprehensive security review. Site administrators are encouraged to audit their user lists for unauthorized accounts and scan for the presence of the "emer-run.php" webshell. The industry now faces the challenge of securing not just the code itself, but the entire pipeline of remote data that modern plugins rely on for functionality.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.