Attackers compromised BdThemes infrastructure and used it to silently take over WordPress sites running several of the company’s plugins. According to Wordfence, a poisoned remote JSON feed exploited a cross-site scripting flaw in the Biggop Library/Biggopti promotional-banner component, causing code to run in logged-in admins’ dashboards and create rogue admin accounts, then install a fake plugin and webshell for persistence. Affected products include Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit; the issue was reportedly active as early as June 23 and remained unpatched at publication.
Why it matters: Site owners using these plugins may already be compromised even if they did not manually update anything, because the attack came through the vendor’s remote API. Administrators should immediately disable or remove affected plugins, inspect for unknown admin users and fake plugins such as emer-run.php, and review server logs for follow-on access.
info@thehackernews.com (The Hacker News)
2026.08.11
99% relevant
This article appears to cover the same BdThemes supply-chain incident, adding that poisoned JSON delivered through the vendor’s update path was used to create rogue WordPress administrator accounts on affected sites.
Bill Toulas
2026.08.10
100% relevant
This article appears to be the first concrete report establishing a distinct BdThemes supply-chain compromise affecting multiple WordPress plugins and customer sites.
← Back to all stories