Observed Signal · Aug 11, 2026 · Security Incident · Source: DEV Community · Impact: 3/5 · Sentiment: Negative
BdThemes Supply-Chain XSS Leads to Web Shells
Wordfence Threat Intelligence reported a critical supply-chain compromise in the BdThemes ecosystem where attackers wrote malicious JSON to the vendor's static storage. A DOM XSS (unescaped display_id in the Biggopti JSON) executed inside logged-in WordPress administrator browsers, causing external scripts (w2.js / x.js) to run. The payloads used administrator sessions to create rogue admin accounts, upload a fake plugin, deploy a web shell (emer-run.php), install MU-plugin persistence, and hide created accounts while beaconing results to a C2. Active attacks were observed on August 7, 2026 and the vendor JSON returned to clean on August 8. Affected plugins include Element Pack, Prime Slider, Pixel Gallery, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste, Smart Admin Assistant.
Supply-chain compromise affecting widely used WordPress plugins can lead to site takeovers, server-side web shells, and hidden admin accounts affecting publishers and enterprise sites; significant for SOCs and publishers but not a platform-level policy change.
Track WordPress Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Wordfence published a PSA on August 8, 2026 describing a supply-chain compromise that poisoned BdThemes' API/JSON responses.
- Attack exploited a DOM XSS via an unescaped display_id in the Biggopti JSON, triggering external scripts (w2.js / x.js) inside administrator browsers.
- Payloads performed rogue administrator creation, uploaded a fake plugin, executed a web shell (emer-run.php), deployed MU-plugins for persistence, and hid accounts while beaconing results to a C2.
- Affected products: Element Pack, Prime Slider, Pixel Gallery, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste, Smart Admin Assistant.
- Active attacks observed August 7, 2026; the malicious endpoint returned clean JSON on August 8, 2026.
Connected Companies & Entities
4 Entities mapped“The compromise did not affect the plugin files on WordPress.org....”
“Content Management Systems (CMS) like WordPress and Elementor are widely used globally for corporate websites, portals, and e-commerce platf...”
“Attackers gained write access to the static storage of BdThemes (equivalent to DigitalOcean Spaces)....”
“Write operations, object versions, access key usage, and Cloudflare access logs on vendor storage buckets....”
Ontology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
Backdoors Found in Dozens of WordPress Plugins
Security researchers discovered a backdoor inserted into dozens of WordPress plug-ins after the plug-in maker Essential Plugin was acquired by a new corporate owner. Anchor Hosting founder Austin Ginder alerted the community after finding the supply‑chain compromise; the malicious code reportedly sat dormant for months and activated earlier in April 2026 to distribute additional malicious payloads to sites running the affected plug-ins. Essential Plugin states it has over 400,000 installs and more than 15,000 customers, while WordPress shows the affected plug-ins in over 20,000 active installations. The plug-ins have been removed from the WordPress directory and marked permanently closed. Site owners are advised to check for and remove any affected plug-ins.
WordPress Plugins Infected with Backdoor
A security researcher, Austin Ginder, discovered that more than 30 WordPress plugins were modified to include a backdoor allowing attackers to inject malicious content into websites. The affected plugins — originally developed by an Indian team called WP Online Support and later sold in early 2025 to an anonymous buyer using the nickname “Kris,” who renamed the collection Essential Plugin — remained dormant until the backdoor was activated in early April 2026. Injected payloads reportedly loaded spam links, redirects, fake pages and crypto-related links from a remote server, and the injections were cloaked so only Google’s crawler could see them. Essential Plugin says the infected addons had over 400,000 installs; the extensions have since been disabled in the WordPress store. Ginder published a patch and a removal recommendation for site operators.
Backdoor in WordPress Plugins Hits 400,000 Installations
A backdoor hidden in more than 30 WordPress plugins has been discovered by web developer Austin Ginder. The plugin collection was originally developed by WP Online Support and reportedly sold in early 2025 to an anonymous buyer using the nickname “Kris,” who renamed it Essential Plugin. The malicious code—activated in early April 2026—injected spam links, redirects, fake pages and crypto links that pointed to public blockchain endpoints; changes were crafted so only Google’s crawler could see them. Essential Plugin reports the affected extensions had over 400,000 installations. WordPress has removed and disabled the extensions from the plugin directory. Users who installed any of the listed plugins are advised to remove them or apply a patch published by Ginder and to audit sites for unauthorized changes.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
