Skip to main content

Tag: bdthemes

3 articles

WordPress admin dashboard on a laptop screen with a cityscape background and office items nearby.

BdThemes Plugins Targeted in Supply Chain Attack

A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

Analyst 207
WordPress plugin developer's workspace with flagged plugins on screen.

BdThemes plugins compromised in supply-chain attack

A stealthy supply-chain attack on BdThemes plugins has turned into a high-stakes problem, putting over 350,000 active WordPress installations at risk. The breach affects popular plugins like Element Pack, Prime Slider, and others, prompting the WordPress Plugins team to swiftly pull them from download.

Analyst 207
WordPress admin dashboard on laptop with blurred promotional banner feed.

WordPress Plugins Targeted by Rogue Feed Exploits

Hackers have found a sneaky way to exploit WordPress plugins, using a promotional banner feed to plant rogue administrator accounts and webshells on live sites - all without modifying a single plugin file. The attack, traced back to an unescaped field in a banner notice, has already hit seven plugins from a popular Elementor add-on vendor.

Analyst 207