Featured image: BdThemes plugins supply-chain hack creates rogue WordPress
IT & Cybersecurity

BdThemes plugins supply-chain hack creates rogue WordPress

A supply-chain hack in BdThemes plugins creates rogue WordPress admins, compromising site security. Learn how the hack happened and what to do next.

August 11, 2026Ehtisham Haider

Introduction

Background on BdThemes and WordPress Plugins

BdThemes is a renowned WordPress plugin developer specializing in sliders, galleries, and page-builder widgets. WordPress powers approximately 40% of all websites globally. Plugins enhance functionality but also increase the vulnerability of a site. With over one million downloads from the official WordPress.org repository, BdThemes plugins have gained popularity among users. Maintaining the quality and security of these plugins is crucial for the overall site security.

The Discovery of the Supply Chain Hack

In August 2026, GBHackers uncovered a supply chain attack involving BdThemes plugins. The attackers inserted malicious code that created unauthorized admin accounts on compromised websites. Additionally, the code deployed a webshell named w2.js, which communicated with an external server. Wordfence traced the vulnerability back to a medium-severity cross-site scripting bug in Prime Slider version 4.1.9. Following the breach revelation, BdThemes promptly halted plugin downloads.

Security experts swiftly issued warnings and urged website administrators to scan for the concealed malware. Many site owners turned to renowned security tools such as Wordfence and Sucuri to detect and eliminate the backdoor.

Photo illustrating IntroductionIllustration for Introduction

The Hack and Its Implications

Technical details of the vulnerability

Researchers found a hidden flaw in the Prime Slider extension. The bug appeared in version 4.1.9 on March 1, 2026. Wordfence classified it as a medium severity cross-site scripting issue. It carries a CVSS score of 5.4. Attackers used this gap to inject malicious CSS animations.

The code ran silently when any admin opened the dashboard.

The payload relied on a script named w2.js. It hijacked the victim browser session without changing official files. GBHackers noted the attackers backdated the files to September 2025. This trick confused timeline tracking. The script then contacted a remote server at ia-cdn[.]com.

It assessed the target environment before deploying further tools.

Attackers then created Must-Use plugin backdoors in the mu-plugins folder. One script enabled magic-link administrative access. Another routine hid the rogue accounts from view. The Hacker News reported that no official repository files were altered. This makes the breach harder to detect than typical supply-chain attacks.

The BdThemes plugins ecosystem faced immediate scrutiny after these findings for Section 1:*

Researchers found a hidden flaw in the Prime Slider extension. The bug appeared in version 4.1.9 on March 1, 2026. Wordfence classified it as a medium severity cross-site scripting issue.

It carries a CVSS score of 5.4. Attackers used this gap to inject malicious CSS animations. The code ran silently when any admin opened the dashboard.

The payload relied on a script named w2.js. It hijacked the victim browser session without changing official files. GBHackers noted the attackers backdated the files to September 2025.

This trick confused timeline tracking. The script then contacted a remote server at ia-cdn[.]com. It assessed the target environment before deploying further tools.

Attackers then created Must-Use plugin backdoors in the mu-plugins folder. One script enabled magic-link administrative access.

Another routine hid the rogue accounts from view.

Illustration related to The Hack and Its ImplicationsVisual context for The Hack and Its Implications

Response and Mitigation

BdThemes' response and plugin updates

BdThemes halted all plugin downloads after the breach. The vendor released a patch for Prime Slider 4.1.9 that removes the XSS vector. Updated releases include a hardened authentication check. Site owners should download the new version from the official BdThemes repository.

WordPress and community response

WordPress core issued an advisory warning about the supply-chain issue. The advisory recommends disabling mu-plugins until verified. Wordfence added a detection rule for the malicious w2.js file. The community shared quick-fix scripts on GitHub. Site owners should run a full security scan and audit admin accounts.

Photo illustrating Response and MitigationIllustration for Response and Mitigation

FAQ

The vulnerability is a medium-severity cross-site scripting (XSS) issue. It was introduced in Prime Slider version 4.1.9. This flaw allowed attackers to inject malicious CSS animations.
Site owners can protect themselves by updating their BdThemes plugins. They should also monitor their site's activity for suspicious behavior. Wordfence recommends keeping all plugins up to date.
Yes, site owners should look for rogue administrator accounts. They should also check for malicious files in the mu-plugins directory. [GBHackers](https://gbhackers.com/wordpress-supply-chain-attack-exploits-bdthemes-plugins) reports that attackers created Must-Use plugin backdoors.
The breach allowed attackers to create rogue administrators and install webshells. The BdThemes plugins team temporarily halted all plugin downloads from the CMS platform. The Hacker News reported on this breach.
Site owners can prevent similar attacks by keeping their plugins up to date. They should also use security plugins like Wordfence to monitor their site's activity. Regularly reviewing user accounts is also important.

Conclusion

The recent supply-chain hack targeting BdThemes plugins for WordPress has highlighted the importance of vigilance and proactive security measures for site owners. By exploiting a cross-site scripting vulnerability in the Prime Slider plugin, attackers were able to create rogue administrator accounts and install webshells on vulnerable sites. The fact that this vulnerability was introduced in a recent version of the plugin and was not immediately detected underscores the need for regular security audits and updates.

WordPress site owners should take immediate action to protect their sites, including updating the Prime Slider plugin to the latest version and running a full security scan to detect any potential malware or backdoors. The BdThemes plugins team's decision to temporarily halt plugin downloads from the CMS platform was a prudent measure to prevent further compromises.

As reported by GBHackers, the attack's complexity and the attackers' ability to backdate files and create stealthy backdoors make it essential for site owners to stay informed and proactive in their security efforts.

The incident also highlights the importance of monitoring plugin updates and security advisories from trusted sources like Wordfence and The Hacker News. By staying informed and taking proactive measures, WordPress site owners can reduce the risk of their sites being compromised and minimize the potential impact of a supply-chain attack on their online presence. The BdThemes plugins supply-chain hack serves as a reminder that security is an ongoing process.

Site owners must remain vigilant to protect their sites and users from evolving threats.

Security teams watching this space also track OpenAI Launches in related coverage.