BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Wordfence has revealed that threat actors are actively exploiting a supply chain compromise affecting multiple BdThemes WordPress plugins by poisoning a remote JSON data stream. This attack leverages an XSS vulnerability in the Biggopti component to inject malicious scripts into the browsers of logged-in administrators, resulting in the creation of rogue admin accounts and the installation of web shells. Affected products include Element Pack Addons for Elementor [bdthemes-element-pack-lite], Live Copy Paste for Elementor [live-copy-paste], Pixel Gallery Addons for Elementor [pixel-gallery], Prime Slider Addons for Elementor [bdthemes-prime-slider-lite], Smart Admin Assistant [smart-admin-assistant], Ultimate Post Kit Addons for Elementor [ultimate-post-kit], and Ultimate Store Kit [ultimate-store-kit]. The WordPress plugins team has temporarily disabled downloads for these items pending a full review.