Security.io Intelligence DeskTuesday, 11 August 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Supply Chain · Executive briefing

Poisoned BdThemes API response converts trusted WordPress sessions into persistence

Attackers changed a remotely fetched promotional feed rather than plugin packages, causing malicious JavaScript to execute when authenticated administrators opened WordPress dashboards.

Supply ChainApplication SecurityIdentity
Why it is in today’s brief

The coding flaw dates to March 2026 and Wordfence identified a possible campaign start in June, but the materially new development is confirmation of active supply-chain compromise and the removal of affected plugins for investigation. It warrants inclusion because the attack bypassed normal update and repository-integrity checks, changing today’s decision from version management to administrator-account review, webshell hunting and governance of remotely fetched content.

Read first

The BdThemes compromise bypassed conventional package-integrity controls by poisoning a vendor-hosted JSON feed consumed inside authenticated WordPress administration pages.

Act now

Inventory WordPress sites running BdThemes plugins.

Accountable owner

Application security leader, web-platform owner, digital operations lead and third-party risk owner

Decision horizon

Identify affected sites and hunt for account or file persistence today; do not await a routine plugin-update cycle.

AssessmentMedium confidence
Emerging riskA BdThemes incident statement, complete affected-version matrix, fixed releases, poisoned endpoint details, campaign infrastructure or independently validated remediation guidance.

What happened

Wordfence was notified on August 7, 2026, of attacks affecting plugins produced by BdThemes. Its investigation found that attackers had not modified packages in the official WordPress.org repository. Instead, they obtained write access to vendor infrastructure and poisoned a static JSON response fetched by an administrative promotional-banner component. Attribution posture: Wordfence did not identify the actor behind the BdThemes compromise.

The Biggopti Library failed to escape the display_id parameter received from the Sigmative API, allowing injected JavaScript to run in an authenticated administrator’s browser. The malicious script used the administrator’s active session to create rogue privileged accounts and manipulated database queries to hide those accounts from the normal user list. An additional payload named w2.js installed a false plugin and created a webshell named emer-run.php for persistence.

Wordfence assessed June 23, 2026, as the earliest possible campaign start supported by available records. WordPress closed the affected plugins on August 8, 2026, pending inspection, and two previously poisoned API endpoints were returning clean JSON by the time of reporting. On August 10, 2026, independent reporting said BdThemes had not published an incident statement. The cited reporting did not reproduce the command-and-control domains or IP addresses associated with the observed activity, and no hashes for w2.js or emer-run.php were published in that report. The cited source did not publish the relevant infrastructure details described as The reporting referenced command-and-control infrastructure without reproducing domains or IP addresses.

Why this matters now

This attack did not depend on customers installing a malicious update. A legitimate plugin dynamically retrieved vendor-controlled content inside wp-admin, and the browser executed the poisoned response with the authority of a logged-in administrator. Package checksums, repository monitoring and conventional update approval would not identify that control path.

The administrative session turned an upstream content failure into local identity abuse and server persistence. A team that merely removes or updates the affected plugin may leave rogue accounts, hidden database entries, a false plugin or emer-run.php on the host. Closure therefore requires compromise assessment rather than a software-only remediation record.

The incident also expands the definition of software supply-chain inventory. Security teams need to understand external APIs, feeds, feature flags, advertisements and templates consumed after installation, particularly when those responses appear within privileged interfaces.

The decision for security leaders

Assign the web-platform owner to identify all BdThemes components across production, staging, development and managed customer sites. Preserve plugin versions, administrative logs, database records, fetched JSON responses and filesystem timestamps before removal or cleanup changes the evidence.

Have incident response reconcile every WordPress administrator against an approved identity and search for the published filenames, unexplained plugins and account-hiding behaviour. Any affected site should remain open as an incident until persistence and downstream data access have been assessed.

Require application security to document remotely fetched content that can influence privileged interfaces. Enforce output encoding, restrictive content security policy where feasible, response validation and a kill switch that does not depend on the compromised supplier infrastructure.

Evidence of closure

  • The site inventory records every installed BdThemes component and owner.
  • Administrator accounts reconcile to approved identities and creation records.
  • Filesystem scanning finds no w2.js, emer-run.php or unexplained plugin persistence.
  • A controlled test confirms remote promotional content cannot execute scripts.

The Security.io assessment

Wordfence provides direct technical evidence of a poisoned vendor response, malicious JavaScript execution, rogue administrator creation and webshell persistence. The absence of a BdThemes statement at the publication cut-off leaves the complete affected-product and fixed-version scope unresolved, so asset owners should not rely on a single version threshold for closure.

The event is supply-chain compromise even though the official plugin packages were unchanged. Risk propagated through an upstream distribution mechanism used after installation. It is also an identity incident because the payload borrowed an authenticated administrator’s authority and attempted to conceal the resulting privileged accounts.

Clean responses from the previously poisoned endpoints reduce ongoing delivery risk but do not establish that customer sites are clean. Evidence-based closure requires account reconciliation, database and filesystem review, and confirmation that other remote BdThemes-controlled resources were not modified.

Questions for the morning meeting

  • Which plugins execute remotely supplied content in privileged pages?
  • Can web teams reconstruct all administrator-account changes?
  • Are package signatures being mistaken for complete supply-chain assurance?
  • Who can suspend a plugin fleet before vendor guidance arrives?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Registration open
Sponsor's Notice · Information Security Network

Security.io Executive Roundtable: The 2027 CISO Agenda

CISO Roundtables & Executive events

View roundtables →
Invitation only
Sponsor's Notice · NoBrowser

Security.io CISO Dinner: The Secure Browser Decision

Virtual PC's & Secure Browsers in the Cloud

Request an invitation →
Black Hat week
Paid Placement · HackerFX

Security.io at Black Hat: Daily Intelligence Briefing

Catch the Daily News Where it Happens First

Follow the Black Hat desk →