Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Supply Chain Breach Affects Popular BdThemes WordPress Plugins

Supply Chain Breach Affects Popular BdThemes WordPress Plugins

Posted on August 11, 2026 By CWS

In a recent cybersecurity incident, BdThemes, a prominent WordPress plugin provider, suffered a supply chain attack that compromised several of its plugins. This prompted the WordPress plugins team to suspend the download of affected plugins temporarily, thereby safeguarding users from potential threats.

Unlike typical supply chain breaches, this attack uniquely involved tampering with a static JSON data stream rather than modifying source code files in the WordPress.org repository, according to Wordfence researcher Paolo Tresso. The unauthorized modification targeted an administrative component that pulls promotional content, thereby injecting malicious scripts.

Affected Plugins and Vulnerabilities

The breach impacted multiple BdThemes plugins, including Element Pack Addons and Live Copy Paste for Elementor, among others. While some plugins have a substantial number of active installations, others have unspecified user counts. Notices on WordPress’s plugin directory indicate closures pending comprehensive reviews.

The vulnerability resides within a component named Biggopti, which fetches promotional banners using JSON files from a DigitalOcean Spaces bucket. A cross-site scripting (XSS) flaw was discovered, attributed to inadequate client-side escaping of data from the Sigmative API. This flaw permits attackers to inject harmful scripts executed during admin page loads.

Attack Mechanics and Payloads

The attack utilized the “api-data-all-records” endpoint to deliver a JavaScript payload termed “w2.js.” This script communicates with a command-and-control (C2) server, potentially creating unauthorized admin accounts and deploying a PHP web shell. Furthermore, it installs persistence modules that facilitate ongoing unauthorized access and conceal malicious activity.

An alternate payload, “x.js,” found on the plugin developer’s infrastructure, generates deterministic admin credentials based on the victim website’s hostname. This method simplifies the attack by eliminating the need for a centralized storage of compromised credentials.

Implications and Future Outlook

This breach underscores significant security concerns within the WordPress ecosystem, highlighting the sophisticated nature of modern supply chain attacks. The campaign’s ultimate objective appears to be establishing covert administrative control and enabling remote code execution across affected websites.

The incident follows closely on the heels of other similar attacks, suggesting a broader trend of targeting WordPress plugins to gain administrative access. The compromised JSON records and payloads point to potential lapses in BdThemes’ cloud storage security or internal infrastructure.

As cybersecurity experts continue to investigate, users are advised to remain vigilant, promptly update affected plugins, and monitor for any unusual activities within their WordPress installations. Ensuring robust security practices and regular audits can help mitigate such risks in the future.

The Hacker News Tags:administrator account, API, BdThemes, Cybersecurity, digital threat, JSON, plugin vulnerability, remote code execution, supply chain attack, web security, Wordfence, WordPress, XSS

Post navigation

Previous Post: OpenAI Enhances Cybersecurity with GPT-5.6-Cyber
Next Post: Mozilla Revokes Exposed Firefox Signing Key

Related Posts

OceanLotus Targets Vietnamese Firms with SPECTRALVIPER OceanLotus Targets Vietnamese Firms with SPECTRALVIPER The Hacker News
How Attackers Bypass Synced Passkeys How Attackers Bypass Synced Passkeys The Hacker News
How Attackers Exploit SOC Workloads Beyond Phishing Emails How Attackers Exploit SOC Workloads Beyond Phishing Emails The Hacker News
Hackers Exploit Milesight Routers to Send Phishing SMS to European Users Hackers Exploit Milesight Routers to Send Phishing SMS to European Users The Hacker News
Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOS Hackers Found Using CrossC2 to Expand Cobalt Strike Beacon’s Reach to Linux and macOS The Hacker News
N-central Servers Breached: Authentication Flaw Exploited N-central Servers Breached: Authentication Flaw Exploited The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Mozilla Revokes Exposed Firefox Signing Key
  • Supply Chain Breach Affects Popular BdThemes WordPress Plugins
  • OpenAI Enhances Cybersecurity with GPT-5.6-Cyber
  • Stealth Loaders in Google Play Apps Deliver Anatsa Malware
  • Critical Red Hat ACM Flaw Allows Cluster-Admin Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Mozilla Revokes Exposed Firefox Signing Key
  • Supply Chain Breach Affects Popular BdThemes WordPress Plugins
  • OpenAI Enhances Cybersecurity with GPT-5.6-Cyber
  • Stealth Loaders in Google Play Apps Deliver Anatsa Malware
  • Critical Red Hat ACM Flaw Allows Cluster-Admin Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark