All incidents

BdThemes WordPress plugin supply chain attack via poisoned JSON feed

incidentopenAug 9, 2026 — Aug 10, 2026
BdThemes WordPress plugins hit by poisoned feed exploit

A supply chain attack targeting BdThemes WordPress plugins has allowed attackers to create rogue administrator accounts without altering any plugin code, as reported by Infosecurity Magazine. The exploit was delivered through a poisoned promotional data feed that gave the adversaries write access to the vendor’s object storage bucket.

The flaw resides in an unescaped field of the promotional banner script used by the plugins, which permits the injection of malicious JSON when the feed is processed. When the malicious JSON is rendered in the WordPress admin dashboard it executes as cross‑site scripting, enabling the creation of hidden admin accounts and the upload of webshells. No CVE identifier has been assigned to the issue at this time.

Two persistent backdoors were installed alongside the rogue accounts, designed to survive plugin updates and to conceal the unauthorized users from site administrators. Because the attack does not modify the plugin files on disk, traditional integrity checks and file‑based scanners often fail to flag the compromise. Access to the compromised storage bucket also allowed the attackers to hijack active sessions and maintain control over affected installations.

Wordfence disclosed the activity on 7 August 2026 after observing anomalous requests to the promotional feed endpoint (Wordfence blog). All seven affected plugins were subsequently taken offline while the vendor investigates the source of the poisoned feed. No specific threat actor has been linked to the campaign, but the technique mirrors recent supply‑chain abuses that exploit trusted third‑party data sources.

Site owners should immediately review their WordPress user tables for any administrator accounts they do not recognise and remove them if found, as highlighted by SecurityOnline. Checking server logs for unexpected PUT or POST requests to the vendor’s storage bucket can reveal whether the feed was abused. Reinstalling the plugins from a clean source once they are returned to the plugin directory will remove any injected scripts, but only after confirming the feed has been secured.

Administrators may also want to disable the promotional banner functionality temporarily until BdThemes releases a patched version. Enforcing strict bucket policies that limit write access to trusted IP addresses reduces the risk of similar feed poisoning attempts. Running a regular integrity scan of the wp‑admin directory and monitoring for unfamiliar JavaScript in dashboard pages can help catch future injections early.

Intelligence briefing updated Aug 10, 2026

Root sourcewww.wordfence.com
Timeline Coverage

Swipe to explore timeline