← Back to feed
Threat Actors & CampaignsEmerging1 sourceAug 10, 2026 · 10:15via CyberPress

BDThemes WordPress Supply Chain Attack Creates Rogue Admins and Deploys Webshells

Brief

A supply chain compromise has hit BdThemes, a popular WordPress plugin vendor, allowing attackers to silently create rogue administrator accounts and install webshells on affected sites without modifying a single line of plugin code.

The Wordfence Team was alerted to the campaign on August 7, 2026, and all impacted plugins have since been pulled from the WordPress repository pending investigation.

Unlike conventional plugin supply chain breaches, no source code in the official WordPress repository was altered

BDThemes WordPress Supply Chain Attack

Instead, threat actors poisoned a static JSON data stream fetched by “Biggopti,” an internal promotional banner system used across BdThemes plugins including Element Pack, Prime Slider, Pixel Gallery, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste, and Smart Admin Assistant.

Read more on CyberPress