Particle.news
Download on the App Store

BdThemes Promotional Feed Hijacked to Seed Rogue WordPress Administrators

Injected JavaScript ran in logged‑in admin dashboards to create hidden administrator accounts, install a webshell, and persist without changing plugin files.

Overview

  • Attackers gained write access to BdThemes object storage and replaced a promotional JSON feed consumed by the Biggopti banner component, turning vendor content into an attack vector.
  • A cross‑site scripting flaw in the Biggop/Biggopti library caused by an unescaped display_id field allowed the injected JSON to execute in administrators’ browsers.
  • Defiant’s Wordfence detected the campaign on Aug. 7 and investigators say the malicious script used administrators’ sessions to create hidden admin accounts and install a fake plugin with a webshell.
  • WordPress.org removed the seven affected BdThemes plugins on Aug. 8 and the poisoned API endpoints were returned to clean JSON, but the vulnerable code path remains unpatched and site owners are urged to audit users, options and WAF logs.
  • Wordfence linked the attack infrastructure to recent supply‑chain incidents and researchers warn this fileless, API‑driven technique makes detection harder and increases the need for vendors to protect remote assets and admin‑facing feeds.