A supply chain attack on BdThemes WordPress plugins exposed administrators to account takeover, webshell deployment, and persistent backdoors This article explores attack bdthemes wordpress. . Wordfence Threat Intelligence was alerted on August 7, 2026, after discovering that hackers poisoned a remote promotional API feed used by several popular BdThemes plugins.
Affected plugins include Element Pack Addons for Elementor, Prime Slider Add-ons for Elementor, Pixel Gallery Add-ons for Elementor, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste, and Smart Admin Assistant. The BdThemes plugins use an internal component called Biggopti to fetch promotional banners from this remote API and display them within the WordPress admin dashboard.
A Supply Chain Attack was discovered where Biggopti failed to properly escape the display_id value from the JSON response, leading to a cross-site scripting vulnerability with a CVSS score of 5.4. The payload utilized an onanimationstart event handler embedded within an injected HTML attribute, enabling it to run silently over the course of milliseconds. A secondary payload, x.js, extracted predictable administrator credentials from the victim's domain name.
Site owners must review WordPress administrator accounts, inspect installed plugins and the Must-Use plugin directory, as well as search for emer-run.php files, suspicious class-wp-query-* files, and the fz_emer_login_tokens database option. This incident highlights how a trusted remote data feed can serve as an effective malware delivery route even when local plugin files remain unchanged.












