Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

BdThemes plugins supply-chain hack creates rogue WordPress admins

0
Medium
Published: 08/10/2026 (08/10/2026, 21:12:10 UTC)
Source: Bleeping Computer

Description

A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 21:22:25 UTC

Technical Analysis

The BdThemes supply-chain attack involved a threat actor gaining write access to the vendor's storage bucket and poisoning a static remote JSON data stream fetched by an administrative promotional banner component in BdThemes WordPress plugins. A coding flaw introduced in March 2026 created a cross-site scripting (XSS) vulnerability in the Biggop Library's JSON response parsing, specifically via the 'display_id' parameter from the Sigmative API. This allowed injection of arbitrary JavaScript that executes in the WordPress admin dashboard whenever an administrator accesses it. The malicious script creates rogue admin accounts that are hidden from the user list and installs a webshell (emer-run.php) through a fake plugin for persistence. The attack is stealthy, API-driven, requires no user interaction or plugin update, and was active from at least June 23 until the plugins were pulled on August 8, 2026. The vendor has not yet issued an official statement or patch, but the poisoned API endpoints now serve clean JSON data.

Potential Impact

The attack enables unauthorized creation of rogue administrator accounts on affected WordPress sites, granting attackers full administrative control. These rogue accounts are hidden from the user list, making detection difficult. The attacker also establishes persistence via a webshell installed as a fake plugin, allowing ongoing remote control. The attack is stealthy, requires no file modification or plugin update, and executes whenever an admin accesses the dashboard, increasing the risk of widespread compromise of sites using affected BdThemes plugins.

Defensive Guidance

As of the report, no official patch or fix has been published by BdThemes. The affected plugins have been removed from the WordPress repository pending investigation, and the malicious API endpoints have been cleaned to serve legitimate JSON data. Site administrators should remove affected BdThemes plugins and monitor for unauthorized admin accounts and suspicious files such as emer-run.php. Until an official fix is released, avoid using BdThemes plugins and follow updates from the vendor and WordPress security teams for remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/","fetched":true,"fetchedAt":"2026-08-10T21:22:02.274Z","wordCount":853}

Threat ID: 6a7a4105bf8831d53990351a

Added to database: 08/10/2026, 21:22:13 UTC

Last enriched: 08/10/2026, 21:22:25 UTC

Last updated: 08/11/2026, 02:07:29 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses