securityonline.info 8/9/2026, 2:06:51 AM · external

BdThemes plugin attack lets hackers hijack WordPress admin panels

BdThemes plugin attack lets hackers hijack WordPress admin panels
CyberSIXT Evidence Panel
Primary Source wordfence.com

A recent supply chain attack targeting BdThemes plugins has been disclosed by Wordfence on August 7, 2026. Attackers poisoned a promotional banner feed to execute cross-site scripting (XSS) within the admin dashboard of WordPress sites using these plugins. This attack allows the creation of rogue administrator accounts, uploading of webshells, and installation of backdoors without modifying the plugin code, making it difficult for traditional detection methods to identify the compromise.

The attack exploits a vulnerability in the Biggopti component of BdThemes plugins, where attackers gained write access to the vendor's storage bucket and injected malicious JSON, leading to session hijacking and control over affected WordPress installations. All affected plugins are currently offline as investigations continue. Users are advised to review their database and plugin directories for signs of compromise.

View Primary Source Via securityonline.info

Article by CyberSIXT