BdThemes WordPress plugin supply-chain hack created hidden administrator accounts on customer sites

Attackers compromised BdThemes infrastructure and used it to silently take over WordPress sites running several of the company’s plugins. According to Wordfence, a poisoned remote JSON feed exploited a cross-site scripting flaw in the Biggop Library/Biggopti promotional-banner component, causing code to run in logged-in admins’ dashboards and create rogue admin accounts, then install a fake plugin and webshell for persistence. Affected products include Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit; the issue was reportedly active as early as June 23 and remained unpatched at publication.
Why it matters: Site owners using these plugins may already be compromised even if they did not manually update anything, because the attack came through the vendor’s remote API. Administrators should immediately disable or remove affected plugins, inspect for unknown admin users and fake plugins such as emer-run.php, and review server logs for follow-on access.

Sources

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
info@thehackernews.com (The Hacker News) 2026.08.11 99% relevant
This article appears to cover the same BdThemes supply-chain incident, adding that poisoned JSON delivered through the vendor’s update path was used to create rogue WordPress administrator accounts on affected sites.
BdThemes plugins supply-chain hack creates rogue WordPress admins
Bill Toulas 2026.08.10 100% relevant
This article appears to be the first concrete report establishing a distinct BdThemes supply-chain compromise affecting multiple WordPress plugins and customer sites.
← Back to all stories