Supply Chain Attack on BdThemes Plugins Compromises WordPress Admin Accounts

Supply Chain Attack on BdThemes Plugins Compromises WordPress Admin Accounts

First seen 10 Aug 2026, 14:02 UTC CybersecuritynewsGbhackersInfosecurity-Magazinewww.wordfence.com 88% similarity 66.0

Article Content

Browse articles
ThreatCluster

A supply chain attack has targeted multiple BdThemes WordPress plugins, allowing attackers to hijack administrator sessions, create unauthorized admin accounts, and deploy persistent web shells. The incident was reported by Wordfence Threat Intelligence on August 7, 2026. Attackers exploited a poisoned remote promotional API feed used by the plugins, impacting site administrators who utilize these themes. The affected plugins include popular options like Element Pack. No modifications to the plugin source code or updates were necessary for the attack to succeed. This incident raises significant security concerns for WordPress users relying on these plugins. The scope of the impact remains unclear, but the potential for widespread exploitation exists due to the popularity of the affected plugins.

Key Points: • Attackers exploited a poisoned API response to compromise BdThemes WordPress plugins. • Unauthorized admin accounts and web shells were created without modifying plugin code. • Wordfence reported the incident on August 7, 2026, highlighting a serious security risk.

ThreatCluster AI How this analysis works

Timeline

2026-08-07
Wordfence notified of supply chain attack
Wordfence Threat Intelligence reported the compromise of BdThemes plugins, revealing unauthorized admin access and web shell deployment.
Gbhackers
2026-08-10
Articles published detailing the attack
Both Gbhackers and Cybersecuritynews published articles outlining the attack methodology and its impact on WordPress sites.
Gbhackers

Community

Browse all →

Tracked Entities in This Story