VMTech
Discuss a project

BdThemes plugin compromise uses poisoned JSON to seize WordPress admin access

BdThemes plugin compromise uses poisoned JSON to seize WordPress admin access

WordPress has temporarily disabled downloads for seven plugins from vendor BdThemes after attackers poisoned remote JSON data used by an administrative promotional-banner component. The affected list includes Element Pack Addons for Elementor, which has more than 100,000 active installs, and Live Copy Paste for Elementor and Ultimate Store Kit, each with 6,000+ active installs.

Plugin-directory listings state that the products were closed on August 7 or 8, 2026, pending a full review. Wordfence said the incident differs from a conventional repository compromise: no source code files were modified in the official WordPress.org repository, and attackers did not need to alter plugin files on a victim’s disk.

Remote banner data became the attack path

The vulnerable component is an internal library called Biggopti. It is bundled with the plugins and retrieves promotional banners from JSON files in a DigitalOcean Spaces bucket, then renders them in the WordPress administrative dashboard.

Wordfence identified insufficient client-side escaping of the display_id parameter in JSON responses from the Sigmative API. An attacker able to modify the API data could inject JavaScript that executes whenever a logged-in administrator opens a wp-admin page. The flaw has a CVSS score of 5.4 and was first introduced in bdthemes-prime-slider-lite on March 1, 2026, before appearing in other plugins.

That execution context gives the campaign a direct route to privileged actions. Wordfence said malicious records were supplied through the api-data-all-records endpoint, allowing a script named w2.js to contact the ia-cdn[.]com/fz/c command-and-control server with the site origin and retrieve targeting instructions.

Payloads establish concealed persistence

If instructed to proceed, w2.js creates a rogue administrator through the WordPress REST API, downloads a fake plugin ZIP through the ordinary plugin-upload form, and deploys a PHP web shell named emer-run.php. It then uses that shell to install two Must-Use plugin modules.

One module provides a magic-login backdoor through the ?_wplogin=<token> URL parameter by targeting the longest-registered administrator. The other alters WordPress database-query handling to hide rogue accounts from the administrative user list and exclude them from the displayed user total. These techniques echo the concealed access mechanisms described in concealed WordPress persistence mechanisms while the JSON delivery path avoids a routine plugin-file change.

Wordfence also found an alternate payload, x.js, on the developer’s infrastructure through the api-data-records endpoint. It generates deterministic credentials from the victim hostname: usernames begin with bd_, while passwords begin with Bd@26!, enabling responders to calculate account indicators for a suspected domain.

What WordPress operators should investigate

The campaign’s apparent objective is covert administrative persistence and remote code execution. The command-and-control infrastructure is assessed as related to recent supply chain incidents involving Advanced Responsive Video Embedder and OptinMonster. Wordfence said the ability to upload malicious JSON and x.js to BdThemes infrastructure points to a serious upstream compromise of cloud-storage credentials or internal systems.

Teams using affected BdThemes plugins should inventory installations, review administrator accounts and Must-Use plugin directories, investigate unexpected plugin uploads, and check for the named payloads and URL-based login mechanism. They should also treat remotely fetched administrative content as privileged attack surface and validate who can modify the storage and API services that supply it.

#wordpress#supplychain#xsssecurity#websecurity
Open analytics
On the site 0 views
min read 4 12.08.2026
Instagram

BdThemes plugin compromise uses poisoned JSON to seize WordPress admin access

Open the post on Instagram ↗