ConicPlex

Start Your Project

A cardboard shipping box with its tamper-evident security tape peeled back and resealed unevenly

On this Page

BdThemes Supply Chain Attack Is Creating Rogue Admins on Elementor Sites

A poisoned JSON feed in BdThemes’ Elementor plugins is creating rogue WordPress admin accounts and installing webshells. Here’s what to check on your site.

Husen Memon

August 15, 2026

A BdThemes supply chain attack disclosed by Wordfence on August 10 is turning a set of popular Elementor addon plugins into rogue admin factories. If your site runs Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, Ultimate Store Kit, Live Copy Paste for Elementor, or Smart Admin Assistant, this is worth checking today rather than the next time you happen to be in the dashboard.

What makes this one unusual is that it doesn’t require an outdated plugin version at all. The attackers didn’t touch any plugin code sitting on your server. They compromised infrastructure on BdThemes’ side instead, which means a site running the newest version of an affected plugin was just as exposed as one running an old one.

How the BdThemes supply chain attack works

Several BdThemes plugins share a component called Biggopti that pulls promotional banner content from a JSON feed hosted on BdThemes’ own cloud storage. According to Wordfence researcher Paolo Tresso, attackers replaced that legitimate JSON response with one carrying a malicious script. Every time a logged-in administrator loaded a wp-admin page on a site with one of these plugins active, the poisoned data executed silently in the browser.

From there, the payload creates a new administrator account through the WordPress REST API and hides it from the normal Users screen, drops a file that acts as a web shell disguised as an installed plugin, and adds a backdoor module to the mu-plugins folder so access survives even after the JSON feed itself gets cleaned up. Wordfence traced confirmed exploitation back to June 23, weeks before this went public.

Which plugins are affected

The plugins named across Wordfence’s advisory and follow-up reporting from The Hacker News and BleepingComputer are:

  • Element Pack Addons for Elementor (100,000+ active installs)
  • Prime Slider Addons for Elementor
  • Ultimate Post Kit Addons for Elementor
  • Pixel Gallery Addons for Elementor
  • Ultimate Store Kit
  • Live Copy Paste for Elementor
  • Smart Admin Assistant

All of them were pulled from the WordPress.org plugin directory on August 7 and 8 pending a full review, and as of this writing there’s no patched release to update to. Deactivating is currently the only fix.

What to do if you run any of these plugins

  1. Deactivate and delete the affected plugin now. Don’t wait for a patched version since none exists yet.
  2. Check your Users list for any administrator account you don’t recognize, then check the wp_users database table directly, since part of the payload’s job is hiding rogue accounts from the standard admin screen.
  3. Look for a file installed as a fake plugin, and check the mu-plugins directory for anything you didn’t put there yourself.
  4. Review access and login logs back to June 23 for anything unusual.
  5. Rotate your WordPress admin passwords and any API keys visible in the dashboard as a precaution, even if you don’t find obvious signs of compromise.

If you’d rather have someone confirm the site is clean than dig through database tables yourself, that kind of check is exactly what a WordPress Development security review covers, and it’s a natural add-on for anyone leaning on Elementor Development work where these addon plugins tend to pile up over time.

Sources

Husen Memon is a co-founder of ConicPlex, a web development agency specializing in WordPress, Webflow, and custom software builds. Over more than 9 years and 200+ client projects, he has worked across everything from plugin development to full platform migrations, with a focus on building sites and tools that hold up under real day-to-day use, not just in a demo. He writes here about the technical decisions and tradeoffs that come up in that work.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Software

Marble consultation counter in a med spa with a tablet, orchid, treatment cards, and a towel, with a treatment room visible in the background

Why a Treatment-Finder Quiz Converts Better Than a Service Menu for Med Spas and Clinics

A treatment-finder quiz can convert far better than a static service list on a med spa or clinic website. Here…

Aftab Memon

September 12, 2026

Plugins

Illustration of a notification bell above a stack of product boxes, representing WooCommerce back in stock notification plugins

Best WooCommerce Back in Stock Notification Plugins: 4 Real Options Compared

WooCommerce has no built-in way to notify a customer when an out-of-stock product comes back. This post compares four real…

Husen Memon

September 11, 2026

News & Updates

A laptop glowing with soft blue, red, yellow, and green light beside a cracked glass cube on a desk, symbolizing a breached browser security boundary

Chrome Patches Its Seventh Actively Exploited Zero-Day of 2026 (CVE-2026-87491)

Google patched CVE-2026-87491, Chrome’s seventh actively exploited zero-day of 2026, in Chrome 153. Here’s what changed and how to update….

Sameer Malek

September 10, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant