CVE Tools

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

The Hacker NewsBy The Hacker News

Reported exploitedWordPressElementor

Our summary

Wordfence has revealed that threat actors are actively exploiting a supply chain compromise affecting multiple BdThemes WordPress plugins by poisoning a remote JSON data stream. This attack leverages an XSS vulnerability in the Biggopti component to inject malicious scripts into the browsers of logged-in administrators, resulting in the creation of rogue admin accounts and the installation of web shells. Affected products include Element Pack Addons for Elementor [bdthemes-element-pack-lite], Live Copy Paste for Elementor [live-copy-paste], Pixel Gallery Addons for Elementor [pixel-gallery], Prime Slider Addons for Elementor [bdthemes-prime-slider-lite], Smart Admin Assistant [smart-admin-assistant], Ultimate Post Kit Addons for Elementor [ultimate-post-kit], and Ultimate Store Kit [ultimate-store-kit]. The WordPress plugins team has temporarily disabled downloads for these items pending a full review.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store