CVE Tools
Back to feed
Exploited in the wild WordPress supply-chain Elementor Wordfence web-app

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Wordfence has revealed that threat actors are actively exploiting a supply chain compromise affecting multiple BdThemes WordPress plugins by poisoning a remote JSON data stream. This attack leverages an XSS vulnerability in the Biggopti component to inject malicious scripts into the browsers of logged-in administrators, resulting in the creation of rogue admin accounts and the installation of web shells. Affected products include Element Pack Addons for Elementor [bdthemes-element-pack-lite], Live Copy Paste for Elementor [live-copy-paste], Pixel Gallery Addons for Elementor [pixel-gallery], Prime Slider Addons for Elementor [bdthemes-prime-slider-lite], Smart Admin Assistant [smart-admin-assistant], Ultimate Post Kit Addons for Elementor [ultimate-post-kit], and Ultimate Store Kit [ultimate-store-kit]. The WordPress plugins team has temporarily disabled downloads for these items pending a full review.