The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 07:52 am AEST · 11 August 2026

BdThemes WordPress plugins compromised in supply-chain attack

BdThemes WordPress plugins compromised in supply-chain attack
Photograph: BleepingComputer

A threat actor compromised BdThemes' upstream infrastructure and modified a remote JSON feed to create rogue administrator accounts on WordPress sites running the company's plugins, according to security firm Defiant's Wordfence division. The attack exploited a cross-site scripting vulnerability in the Biggop Library component responsible for fetching promotional banners, allowing the attacker to inject malicious JavaScript that used legitimate administrators' sessions to create hidden admin accounts and install webshells, BleepingComputer reports.

Wordfence detected the attacks starting August 7, with evidence suggesting the campaign began as early as June 23. The affected plugins—including Element Pack, which has over 100,000 active installations—were removed from WordPress.org on August 8 pending review. The vulnerability was assigned a "medium" severity score and remains unpatched as of publication, Defiant said. Researchers traced the command-and-control infrastructure to the same attacker behind recent compromises of Advanced Responsive Video Embedder and OptinMonster.

BdThemes plugins supply-chain hack creates rogue WordPress admins A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. bleepingcomputer.com
cybersecuritywordpresssupply-chainsupply-chain-attackmalware

Follow the live coverage →

BdThemes WordPress plugins compromised in supply-chain attack | The Financial Register Inward Money