A recent security vulnerability affecting seven WordPress plugins allowed attackers to create rogue administrator accounts without modifying any plugin files. The exploit occurred through a poisoned promotional data feed, giving attackers write access to an object storage bucket. The compromised plugins, associated with BdThemes, were taken offline for review after the discovery by Wordfence. The issue stemmed from an unescaped field in a promotional banner script, which permitted the injection of malicious code.
Two persistent backdoors were installed, allowing unauthorized access and concealing the rogue accounts from site administrators. Site owners are urged to audit their systems for potential compromises.