In a recent cybersecurity incident, a supply chain attack has targeted WordPress plugins developed by BdThemes, exposing site administrators to significant security risks. The attack was brought to light by Wordfence Threat Intelligence on August 7, 2026, after detecting tampered API responses used by these popular plugins.
Compromised Plugins and Their Impact
The plugins affected in this attack include Element Pack Addons for Elementor, Prime Slider Addons for Elementor, among others. As a precaution, the WordPress Plugins team has temporarily suspended these plugins from the official repository to conduct an in-depth investigation. Interestingly, the attackers did not alter the source code within the WordPress.org repository, but instead targeted a static JSON data feed hosted on DigitalOcean Spaces, secured via Cloudflare.
The compromised data feed was used by a component called Biggopti in BdThemes plugins to display promotional banners in the WordPress admin dashboard. The attack exploited a vulnerability in this component, specifically a cross-site scripting flaw identified by Wordfence, with a CVSS score of 5.4.
Technical Details of the Attack
The attackers manipulated the display_id value in the JSON response, creating a vulnerability in the HTML id attribute. This allowed a cross-site scripting attack, which executed malicious JavaScript when a WordPress administrator accessed the admin page. The script, embedded in an onanimationstart event handler, silently executed within milliseconds, fetching additional payloads from an attacker-controlled infrastructure.
The primary malicious script, w2.js, communicated with a command-and-control server to determine target validity. If a target was approved, it used the administrator’s WordPress nonce to generate a rogue admin account. Additionally, it installed a fake plugin named wp-smart-thumbnails, containing a webshell for remote command execution, ensuring persistent access to the compromised site.
Response and Mitigation Strategies
Wordfence’s investigation suggests the attack may have commenced on June 23, 2026. Although the compromised API endpoints were addressed by August 8, administrators are advised to examine their systems for signs of compromise. It is crucial to review administrator accounts, inspect installed plugins, and check for suspicious files, such as emer-run.php.
This incident highlights the vulnerabilities in trusted remote data feeds, serving as a reminder of the importance of robust security measures. Site owners should remain vigilant and consider integrating advanced threat detection tools to safeguard their environments.
To bolster your security operations center (SOC), consider accelerating threat detection and streamlining investigations with tools like ANY.RUN for enhanced protection.
