Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Plugins Vulnerable in New Supply Chain Attack

WordPress Plugins Vulnerable in New Supply Chain Attack

Posted on August 10, 2026 By CWS

In a recent cybersecurity incident, a supply chain attack has targeted WordPress plugins developed by BdThemes, exposing site administrators to significant security risks. The attack was brought to light by Wordfence Threat Intelligence on August 7, 2026, after detecting tampered API responses used by these popular plugins.

Compromised Plugins and Their Impact

The plugins affected in this attack include Element Pack Addons for Elementor, Prime Slider Addons for Elementor, among others. As a precaution, the WordPress Plugins team has temporarily suspended these plugins from the official repository to conduct an in-depth investigation. Interestingly, the attackers did not alter the source code within the WordPress.org repository, but instead targeted a static JSON data feed hosted on DigitalOcean Spaces, secured via Cloudflare.

The compromised data feed was used by a component called Biggopti in BdThemes plugins to display promotional banners in the WordPress admin dashboard. The attack exploited a vulnerability in this component, specifically a cross-site scripting flaw identified by Wordfence, with a CVSS score of 5.4.

Technical Details of the Attack

The attackers manipulated the display_id value in the JSON response, creating a vulnerability in the HTML id attribute. This allowed a cross-site scripting attack, which executed malicious JavaScript when a WordPress administrator accessed the admin page. The script, embedded in an onanimationstart event handler, silently executed within milliseconds, fetching additional payloads from an attacker-controlled infrastructure.

The primary malicious script, w2.js, communicated with a command-and-control server to determine target validity. If a target was approved, it used the administrator’s WordPress nonce to generate a rogue admin account. Additionally, it installed a fake plugin named wp-smart-thumbnails, containing a webshell for remote command execution, ensuring persistent access to the compromised site.

Response and Mitigation Strategies

Wordfence’s investigation suggests the attack may have commenced on June 23, 2026. Although the compromised API endpoints were addressed by August 8, administrators are advised to examine their systems for signs of compromise. It is crucial to review administrator accounts, inspect installed plugins, and check for suspicious files, such as emer-run.php.

This incident highlights the vulnerabilities in trusted remote data feeds, serving as a reminder of the importance of robust security measures. Site owners should remain vigilant and consider integrating advanced threat detection tools to safeguard their environments.

To bolster your security operations center (SOC), consider accelerating threat detection and streamlining investigations with tools like ANY.RUN for enhanced protection.

Cyber Security News Tags:API vulnerability, BdThemes, cross-site scripting, Cybersecurity, Malware, PlugIns, supply chain attack, Webshell, Wordfence, WordPress

Post navigation

Previous Post: Malicious VS Code Extensions Target Crypto Wallets
Next Post: Levi Strauss Reports Data Breach from Cyberattack

Related Posts

Cybercriminals Exploit Indian Student Data for Fraud Cybercriminals Exploit Indian Student Data for Fraud Cyber Security News
WordPress GravityForms Plugin Hacked to Include Malicious Code WordPress GravityForms Plugin Hacked to Include Malicious Code Cyber Security News
CISA Alerts on FileZen Vulnerability Exploitation CISA Alerts on FileZen Vulnerability Exploitation Cyber Security News
CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation Cyber Security News
G_Wagon npm Package Attacking Users to Exfiltrates Browser Credentials using Obfuscated Payload G_Wagon npm Package Attacking Users to Exfiltrates Browser Credentials using Obfuscated Payload Cyber Security News
Spotting Phishing-to-RMM Threats Early Spotting Phishing-to-RMM Threats Early Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical SQL Flaw Patched by Metabase Amid Zero-Day Exploit
  • Kimsuky Deploys AsyncRAT Using AI and GitHub Tactics
  • Hackers Exploit Private APN to Target Polish Energy Facility
  • Claude Opus 5 Reduces Prompt Injection Attacks to 2%
  • Levi Strauss Reports Data Breach from Cyberattack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical SQL Flaw Patched by Metabase Amid Zero-Day Exploit
  • Kimsuky Deploys AsyncRAT Using AI and GitHub Tactics
  • Hackers Exploit Private APN to Target Polish Energy Facility
  • Claude Opus 5 Reduces Prompt Injection Attacks to 2%
  • Levi Strauss Reports Data Breach from Cyberattack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark