Several WordPress plugins from BdThemes have been caught in a supply-chain attack that allowed attackers to create hidden administrator accounts and install backdoors on websites without modifying the plugin files themselves.
BdThemes develops a range of WordPress tools, including Element Pack, Prime Slider, Pixel Gallery, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste and Smart Admin Assistant. The affected plugins were temporarily closed on the official WordPress plugin directory while the WordPress Plugins team investigates the incident.
The attack was discovered by Wordfence researchers after they began seeing malicious activity on August 7. Rather than modifying the plugins distributed through WordPress.org, the attackers compromised a remote data source used by BdThemes to deliver promotional banners inside the WordPress administration dashboard.
The problem was made possible by a cross-site scripting vulnerability in the Biggopti component used by several BdThemes plugins. The vulnerable code failed to properly escape a value called “display_id” received from the vendor’s remote API. This meant an attacker who gained control of the API’s data could inject malicious JavaScript into the WordPress admin interface. Wordfence rated the vulnerability medium severity with a CVSS score of 5.4 and listed it as unpatched at the time of its report.
According to Wordfence, the vulnerability was introduced into Prime Slider in March 2026 and was later included in other plugins. The attackers subsequently obtained write access to the vendor’s cloud storage and replaced legitimate JSON responses with specially crafted data containing malicious code.
Once an administrator opened a WordPress dashboard page, the poisoned response could trigger the malicious JavaScript inside the administrator’s authenticated browser session. The attackers could then use that session to create a new administrator account on the affected website.
The attack did not stop there. Wordfence found evidence that the attackers could install a fake plugin containing a webshell and deploy additional components designed to maintain access. Another component could hide rogue administrator accounts from the normal WordPress user list, making the compromise harder for website owners to detect.
One of the most concerning aspects of the incident is that victims did not need to install a malicious plugin update. The attack was delivered through the remote API response, meaning the plugin files on the website could remain unchanged while malicious code was executed in the administrator’s browser. This also means traditional file-integrity checks may not immediately reveal the compromise.
Wordfence says the earliest possible start of the campaign was June 23, when the malicious promotional data could have begun reaching affected sites. The security team captured evidence of the poisoned API responses on August 6 and 7, while the affected plugins were closed on the WordPress directory on August 7. The two compromised API endpoints were returning clean JSON data by August 8.
Researchers also found that the infrastructure used in this campaign appears to be connected to the same threat actors previously associated with supply-chain attacks involving the Advanced Responsive Video Embedder and OptinMonster WordPress plugins.
Wordfence recommends that website owners using the affected BdThemes plugins immediately check their WordPress administrator accounts, plugin directories and database for signs of unauthorized changes. In particular, administrators should look for unfamiliar accounts, suspicious plugins and unexpected files or database entries associated with the attack.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The affected plugins identified by Wordfence include Element Pack Addons for Elementor, Prime Slider Addons for Elementor, Pixel Gallery Addons for Elementor, Ultimate Post Kit Addons for Elementor, Ultimate Store Kit, Live Copy Paste for Elementor and Smart Admin Assistant.
BdThemes WordPress Plugins Hit by Stealthy Supply-Chain Attack





