BdThemes WordPress plugins compromised in supply-chain attack

A threat actor compromised BdThemes' upstream infrastructure and modified a remote JSON feed to create rogue administrator accounts on WordPress sites running the company's plugins, according to security firm Defiant's Wordfence division. The attack exploited a cross-site scripting vulnerability in the Biggop Library component responsible for fetching promotional banners, allowing the attacker to inject malicious JavaScript that used legitimate administrators' sessions to create hidden admin accounts and install webshells, BleepingComputer reports.
Wordfence detected the attacks starting August 7, with evidence suggesting the campaign began as early as June 23. The affected plugins—including Element Pack, which has over 100,000 active installations—were removed from WordPress.org on August 8 pending review. The vulnerability was assigned a "medium" severity score and remains unpatched as of publication, Defiant said. Researchers traced the command-and-control infrastructure to the same attacker behind recent compromises of Advanced Responsive Video Embedder and OptinMonster.