Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

WordPress Plugins Compromised Without a Single File Change

August 10, 2026

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

August 10, 2026

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

August 10, 2026
Facebook X (Twitter) Instagram
Monday, August 10
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»WordPress Plugins Compromised Without a Single File Change
News

WordPress Plugins Compromised Without a Single File Change

Team-CWDBy Team-CWDAugust 10, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Seven WordPress plugins have been used to plant rogue administrator accounts and webshells on live sites without a single plugin file being modified. Instead, attackers poisoned a promotional data feed the plugins load into the admin dashboard.

Wordfence was notified of the compromise on August 7 and published its analysis the following day. It affects BdThemes, an Elementor add-on vendor whose plugins are distributed through the official WordPress.org directory, and all seven have been temporarily closed pending review.

Nothing changed in the repository. The plugins ship a component called Biggopti that pulls promotional banners from the vendor’s API, and attackers obtained write access to the object storage bucket behind it, swapping legitimate responses for crafted payloads.

Read more on WordPress supply chain attacks: Attackers Hijack Popular WordPress Plugins to Deploy Backdoors

An Unescaped Field in a Banner Notice

The vulnerability was introduced by BdThemes itself. Wordfence traced it through SVN history to March 1, when a script added to Prime Slider began concatenating a field from the remote JSON response directly into an HTML attribute without escaping it.

A neighboring attribute in the same code is escaped correctly, which Wordfence reads as an oversight rather than intent. A sanitizer added in May left the flawed attribute untouched.

Because the script runs on every wp-admin page load, the injected code fires silently in the browser of any logged-in administrator. The vulnerability record rates it 5.4, medium severity, and lists it as unpatched.

Rogue Admins and Hidden Accounts

The payload used the administrator’s own session token to create a new administrator through the WordPress REST API, then installed a fake plugin carrying a webshell.

That webshell deployed two persistence modules. One grants unauthenticated administrative access through a URL parameter. The other hooks database queries to hide the rogue accounts from the user list and adjust user counts to match.

A second payload, hosted on BdThemes’ own infrastructure, derived administrator credentials from the victim’s hostname, meaning responders can compute exactly what to hunt for.

Wordfence linked the C2 domain to the actors behind the Advanced Responsive Video Embedder and OptinMonster compromises of the past two months, and said a payload sitting in the vendor’s own bucket points to a serious upstream compromise.

Both endpoints were clean by August 8. Because plugin files were never modified, Wordfence urged site owners to audit database user lists, plugin directories and the options table for indicators of compromise.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNew OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
Team-CWD
  • Website

Related Posts

News

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

August 10, 2026
News

“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Co

August 10, 2026
News

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

August 10, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why that next data breach alert could be a trap

April 18, 2026

How the always-on generation can level up their cybersecurity game

September 11, 2025

What it takes to fool facial recognition

March 14, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.