BdThemes hit by network compromise
Incident
Summary
Hide ▲
Show ▼
A BdThemes WordPress plugin supply-chain compromise planted rogue administrator accounts and webshells on live sites, risking full site control. The malicious payload rode through the Biggopti promotional feed loaded into wp-admin, so the plugins could be abused without any plugin file changes. Wordfence said the affected plugins were later temporarily closed pending review.
Related Happenings
Prime Slider unescaped HTML attribute security flaw
Vulnerability
H score17
First: 10.08.2026 17:30
Last: 10.08.2026 17:30
Sources 1
How related:
The vulnerability was introduced by BdThemes itself. Wordfence traced it through SVN history to March 1, when a script added to Prime Slider began concatenating a field from the remote JSON response directly into an HTML attribute without escaping it.
About this happening:
Prime Slider contains an unescaped remote JSON field flaw in an HTML attribute, leaving logged-in administrators exposed to silent browser-side execution on wp-a...
Prime Slider unescaped HTML attribute security flaw
VulnerabilityHow related: The vulnerability was introduced by BdThemes itself. Wordfence traced it through SVN history to March 1, when a script added to Prime Slider began concatenating a field from the remote JSON response directly into an HTML attribute without escaping it.
About this happening: Prime Slider contains an unescaped remote JSON field flaw in an HTML attribute, leaving logged-in administrators exposed to silent browser-side execution on wp-a...
Creative Mail plugin SQL injection SQL injection flaw (CVE-2026-3985)
Vulnerability
H score50
First: 15.07.2026 17:01
Last: 15.07.2026 17:01
Sources 1
About this happening:
A SQL injection flaw in the Creative Mail plugin exposes database read access, including admin hashes and secret tokens. The issue is tracked as CVE-2026-398...
Creative Mail plugin SQL injection SQL injection flaw (CVE-2026-3985)
VulnerabilityAbout this happening: A SQL injection flaw in the Creative Mail plugin exposes database read access, including admin hashes and secret tokens. The issue is tracked as CVE-2026-398...
ShapedPlugin hit by network compromise
Incident
H score19
First: 18.06.2026 15:55
Last: 18.06.2026 15:55
Sources 1
About this happening:
ShapedPlugin suffered a supply-chain compromise that pushed infected WordPress plugin releases to paying customers through the vendor's official update system, put...
ShapedPlugin hit by network compromise
IncidentAbout this happening: ShapedPlugin suffered a supply-chain compromise that pushed infected WordPress plugin releases to paying customers through the vendor's official update system, put...
PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign
Campaign
H score89
First: 15.06.2026 12:59
Last: 15.06.2026 12:59
Sources 1
About this happening:
A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...
PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign
CampaignAbout this happening: A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...
Latest development: 15.06.2026 20:37
Awesome Motive said a server in its environment was compromised after exploitation of a known UpdraftPlus WordPress plugin flaw, allowing attackers to steal the CDN API key for a marketing website and modify JavaScript distributed through the company’s CDN. The company remediated the marketing site, moved it to a new server, and rotated all credentials, including the CDN API key, while stating that its application servers, source code, and account-data systems were not breached.
Everest Forms Pro plugin patch for CVE-2026-3300
Security Patch Release
H score43
First: 06.06.2026 17:09
Last: 06.06.2026 17:09
Sources 1
About this happening:
The Everest Forms developer released a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw affec...
Everest Forms Pro plugin patch for CVE-2026-3300
Security Patch ReleaseAbout this happening: The Everest Forms developer released a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw affec...
Timeline
-
10.08.2026 17:30 1 articles · 2h ago
Prime Slider script adds an unescaped HTML attribute sink
Technical Analysis UpdateA March 1 Prime Slider change in BdThemes' code concatenated a field from the remote JSON response directly into an HTML attribute without escaping it, leaving a browser-executed path in the wp-admin banner code and showing the unsafe attribute was introduced by oversight.
Show sources
- WordPress Plugins Compromised Without a Single File Change — www.infosecurity-magazine.com — 10.08.2026 17:30
-
08.08.2026 03:00 2 articles · 2d ago
Wordfence discloses a BdThemes plugin supply-chain compromise
Initial DisclosureWordfence disclosed a BdThemes WordPress supply-chain compromise after attackers poisoned the Biggopti promotional API feed, used wp-admin page loads to create rogue administrator accounts and install a webshell on live sites, and caused all seven affected plugins to be temporarily closed pending review.
Show sources
- WordPress Plugins Compromised Without a Single File Change — www.infosecurity-magazine.com — 10.08.2026 17:30
- WordPress Plugins Compromised Without a Single File Change — www.infosecurity-magazine.com — 10.08.2026 17:30