Find notable cyber news and cases, enriched with sources, timelines, and signals.

BdThemes hit by network compromise

Incident
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

A BdThemes WordPress plugin supply-chain compromise planted rogue administrator accounts and webshells on live sites, risking full site control. The malicious payload rode through the Biggopti promotional feed loaded into wp-admin, so the plugins could be abused without any plugin file changes. Wordfence said the affected plugins were later temporarily closed pending review.

Related Happenings

Prime Slider unescaped HTML attribute security flaw

Vulnerability
H score17 First: 10.08.2026 17:30 Last: 10.08.2026 17:30 Sources 1

How related: The vulnerability was introduced by BdThemes itself. Wordfence traced it through SVN history to March 1, when a script added to Prime Slider began concatenating a field from the remote JSON response directly into an HTML attribute without escaping it.

About this happening: Prime Slider contains an unescaped remote JSON field flaw in an HTML attribute, leaving logged-in administrators exposed to silent browser-side execution on wp-a...

Creative Mail plugin SQL injection SQL injection flaw (CVE-2026-3985)

Vulnerability
H score50 First: 15.07.2026 17:01 Last: 15.07.2026 17:01 Sources 1

About this happening: A SQL injection flaw in the Creative Mail plugin exposes database read access, including admin hashes and secret tokens. The issue is tracked as CVE-2026-398...

ShapedPlugin hit by network compromise

Incident
H score19 First: 18.06.2026 15:55 Last: 18.06.2026 15:55 Sources 1

About this happening: ShapedPlugin suffered a supply-chain compromise that pushed infected WordPress plugin releases to paying customers through the vendor's official update system, put...

PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign

Campaign
H score89 First: 15.06.2026 12:59 Last: 15.06.2026 12:59 Sources 1

About this happening: A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...

Latest development: 15.06.2026 20:37

Awesome Motive said a server in its environment was compromised after exploitation of a known UpdraftPlus WordPress plugin flaw, allowing attackers to steal the CDN API key for a marketing website and modify JavaScript distributed through the company’s CDN. The company remediated the marketing site, moved it to a new server, and rotated all credentials, including the CDN API key, while stating that its application servers, source code, and account-data systems were not breached.

Everest Forms Pro plugin patch for CVE-2026-3300

Security Patch Release
H score43 First: 06.06.2026 17:09 Last: 06.06.2026 17:09 Sources 1

About this happening: The Everest Forms developer released a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw affec...

Timeline

  1. 10.08.2026 17:30 1 articles · 2h ago

    Prime Slider script adds an unescaped HTML attribute sink

    Technical Analysis Update

    A March 1 Prime Slider change in BdThemes' code concatenated a field from the remote JSON response directly into an HTML attribute without escaping it, leaving a browser-executed path in the wp-admin banner code and showing the unsafe attribute was introduced by oversight.

    Show sources
  2. 08.08.2026 03:00 2 articles · 2d ago

    Wordfence discloses a BdThemes plugin supply-chain compromise

    Initial Disclosure

    Wordfence disclosed a BdThemes WordPress supply-chain compromise after attackers poisoned the Biggopti promotional API feed, used wp-admin page loads to create rogue administrator accounts and install a webshell on live sites, and caused all seven affected plugins to be temporarily closed pending review.

    Show sources