HomeSecurityBdThemes Plugins: Supply Chain Attack Creates Hidden Administrators

BdThemes Plugins: Supply Chain Attack Creates Hidden Admins

A supply chain attack is affecting popular BdThemes WordPress plugins, as compromised remote data flow allowed attackers to target website administrators. The attack could lead to new administrator accounts and the installation of persistent backdoors.

BdThemes plugins and WordPress attack

BleepingComputer reported on August 10 that the mechanism did not require tampering with plugin files on WordPress.org. Instead, the attackers targeted the infrastructure that served advertising content to the admin area.

See also: ShapedPlugin update system breach infected WordPress sites

How BdThemes plugins were affected

According to the technical analysis published by CybersecurityNews and attributed to Wordfence researchers, the following were affected: Element Pack Addons for Elementor, Prime Slider Addons for Elementor, Pixel Gallery Addons for Elementor, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste, and Smart Admin Assistant.

The plugins used the internal Biggopti component to pull ad frames from a static JSON feed. The feed was hosted on DigitalOcean Spaces and protected by Cloudflare, but the display_id was not secured before being embedded in an HTML element in the admin panel.

This vulnerability allowed JavaScript code to be injected into wp-admin when an administrator was logged in. The malicious value triggered an onanimationstart and then loaded additional files from infrastructure controlled by the attackers.

The case highlights a less obvious risk: the code of plugins can remain unchanged, while the content loaded during their operation becomes an attack vector. For an administrator, the appearance of a supposedly innocent box in wp-admin was enough to trigger the chain.

The researchers noted that the script was designed to remain discreet and target environments with an active high-privilege account. This shifts the detection burden from updates to monitoring sessions, user changes, and new files within the site.

Malicious JSON stream in WordPress

From JavaScript to hidden manager

The main w2.js communicated with ia-cdn[.]com/fz/c and leveraged the nonce of the active session to create a new administrator account. A second file, x.js, allegedly generated predictable login credentials based on the website name.

The sequel was particularly dangerous for e-commerce websites and corporate blogs. The malware could install a fake plugin with a name like wp-smart-thumbnails, which contained emer-run.php, a webshell for remote command execution.

Colonel Server 's independent investigation also documented a hidden login mechanism, the fz_emer_login_tokens database option , and the _wplogin special parameter . The same investigation clarifies that it does not prove that a legitimate BdThemes plugin was the initial cause of the breach.

See also: ACSC: Massive CMS and plugin exploitation campaign leads to webshells

Hidden admin in WordPress

What administrators should check

The affected extensions were temporarily shut down in the official WordPress directory, while the compromised feeds were cleaned up on August 8. However, this is not enough for websites that already loaded the malicious JavaScript, as accounts and backdoors may still remain.

The SecNews technical team recommends checking all administrator accounts, recent plugin installations, and the Must-Use plugins folder. Pay special attention to emer-run.php files , class-wp-query-* names, the fz_emer_login_tokens option , and accounts with the bd_ prefix .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

In case of suspicious activity in BdThemes plugins, it is necessary to isolate the site, delete unauthorized accounts and plugins, change passwords and refresh WordPress salts. At the same time, the log files should be examined for access to ia-cdn[.]com and for actions of creating users or uploading plugins.

See also: wp2shell exploit: Public PoCs for critical WordPress RCE

WordPress website security check

The case shows that a trusted local installation is not automatically protected from a compromised remote service. BdThemes plugins can work without any changes to their code, while the chain of trust ends at the admin panel and the accounts with the highest privileges.

The timing is particularly important: Wordfence reportedly detected evidence dating back to June 23, was notified of the incident on August 7, and saw the compromised feeds cleaned up a day later. So the audit should also cover backups, logs, and accounts created before service was restored.

The practical implication for administrators is to treat any remote content that appears in wp-admin as part of the attack surface. Permission segmentation, user change tracking, and plugin installation restrictions reduce the likelihood of a similar breach turning into a full-blown takeover.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS