BdThemes Supply-Chain Attack Compromises 350,000+ WordPress Sites
A threat actor breached the upstream infrastructure of BdThemes, a developer of premium WordPress plugins, and injected malicious code into a remote JSON feed used by administrative dashboards. The attack, first detected by Wordfence on August 7, exploited a cross-site scripting (XSS) vulnerability in the Biggop Library, a component used to fetch promotional banners from BdThemes’ API.
The flaw, introduced in March 2026, allowed attackers to replace legitimate JSON responses with malicious JavaScript. When executed in an administrator’s browser, the code created rogue admin accounts and installed a webshell (emer-run.php) disguised as a fake plugin for persistence. The attack was stealthy, requiring no user interaction or file modifications, and manipulated database queries to hide the rogue accounts from the WordPress user list.
Wordfence linked the campaign to the same threat actor behind recent supply-chain compromises of Advanced Responsive Video Embedder and OptinMonster, with the earliest signs of activity dating back to June 23. The affected plugins including Element Pack (100,000+ active installs), Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit were pulled from WordPress.org on August 8 pending a full review. While two poisoned API endpoints now return clean data, the vulnerability remains unpatched as of the report’s publication.
BdThemes has not issued an official statement, and the total number of compromised sites remains unclear. The developer’s portfolio claims over 350,000 active installations.
BdThemes Limited cybersecurity rating report: https://www.rankiteo.com/company/bdthemes
"id": "BDT1786400621",
"linkid": "bdthemes",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '350,000+ WordPress sites',
'industry': 'WordPress Plugins',
'name': 'BdThemes',
'size': '350,000+ active installations',
'type': 'Software Developer'}],
'attack_vector': 'Compromised upstream infrastructure (remote JSON feed)',
'date_detected': '2024-08-07',
'date_publicly_disclosed': '2024-08-08',
'description': 'A threat actor breached the upstream infrastructure of '
'BdThemes, a developer of premium WordPress plugins, and '
'injected malicious code into a remote JSON feed used by '
'administrative dashboards. The attack exploited a cross-site '
'scripting (XSS) vulnerability in the Biggop Library, allowing '
'attackers to replace legitimate JSON responses with malicious '
'JavaScript. This created rogue admin accounts and installed a '
'webshell for persistence.',
'impact': {'brand_reputation_impact': 'Potential damage to BdThemes and '
'affected WordPress site owners',
'operational_impact': 'Rogue admin accounts, webshell '
'installation, potential unauthorized access',
'systems_affected': 'WordPress sites using BdThemes plugins'},
'initial_access_broker': {'backdoors_established': 'Rogue admin accounts, '
'webshell (emer-run.php)',
'entry_point': 'Compromised remote JSON feed',
'reconnaissance_period': 'Earliest signs of '
'activity on June 23, '
'2024'},
'investigation_status': 'Ongoing (vulnerability unpatched as of report '
'publication)',
'post_incident_analysis': {'root_causes': 'Unpatched XSS vulnerability in '
'Biggop Library (introduced in '
'March 2024)'},
'references': [{'source': 'Wordfence'}],
'response': {'containment_measures': 'Affected plugins pulled from '
'WordPress.org on August 8',
'third_party_assistance': 'Wordfence'},
'threat_actor': 'Same threat actor behind Advanced Responsive Video Embedder '
'and OptinMonster compromises',
'title': 'BdThemes Supply-Chain Attack Compromises 350,000+ WordPress Sites',
'type': 'Supply-Chain Attack',
'vulnerability_exploited': 'Cross-site scripting (XSS) in Biggop Library'}