Find notable cyber news and cases, enriched with sources, timelines, and signals.

BdThemes hit by network compromise

Incident
First reported
Last updated
Happening score
H score 17
3 unique sources, 3 articles

Summary

Hide ▲

A BdThemes WordPress plugin supply-chain compromise let attackers poison the Biggopti promotional API feed and trigger browser-executed code in wp-admin pages, leading to rogue administrator accounts and a webshell on impacted sites. Wordfence said attacks were seen starting August 7, and the earliest possible campaign start was June 23; the affected plugins were later temporarily closed pending review. A later analysis tied the browser path to a March 1 code change in Prime Slider that concatenated an unescaped JSON field into an HTML attribute. The compromise affected BdThemes products including Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit.

Related Happenings

Prime Slider unescaped HTML attribute security flaw

Vulnerability
H score17 First: 10.08.2026 17:30 Last: 10.08.2026 17:30 Sources 1

How related: The vulnerability was introduced by BdThemes itself. Wordfence traced it through SVN history to March 1, when a script added to Prime Slider began concatenating a field from the remote JSON response directly into an HTML attribute without escaping it.

About this happening: Prime Slider contains an unescaped remote JSON field flaw in an HTML attribute, leaving logged-in administrators exposed to silent browser-side execution on wp-a...

Creative Mail plugin SQL injection SQL injection flaw (CVE-2026-3985)

Vulnerability
H score50 First: 15.07.2026 17:01 Last: 15.07.2026 17:01 Sources 1

About this happening: A SQL injection flaw in the Creative Mail plugin exposes database read access, including admin hashes and secret tokens. The issue is tracked as CVE-2026-398...

ShapedPlugin hit by network compromise

Incident
H score19 First: 18.06.2026 15:55 Last: 18.06.2026 15:55 Sources 1

About this happening: ShapedPlugin suffered a supply-chain compromise that pushed infected WordPress plugin releases to paying customers through the vendor's official update system, put...

PushEngage, OptinMonster, and TrustPulse CDN script-tampering campaign

Campaign
H score89 First: 15.06.2026 12:59 Last: 15.06.2026 12:59 Sources 1

About this happening: A multi-plugin supply-chain campaign targeted Awesome Motive WordPress plugins OptinMonster, TrustPulse, and PushEngage, with malicious JavaScript delivered th...

Latest development: 15.06.2026 20:37

Awesome Motive said a server in its environment was compromised after exploitation of a known UpdraftPlus WordPress plugin flaw, allowing attackers to steal the CDN API key for a marketing website and modify JavaScript distributed through the company’s CDN. The company remediated the marketing site, moved it to a new server, and rotated all credentials, including the CDN API key, while stating that its application servers, source code, and account-data systems were not breached.

PushEngage hit by cyberattack

Incident
H score93 First: 15.06.2026 12:59 Last: 15.06.2026 12:59 Sources 1

About this happening: Awesome Motive's WordPress plugin delivery paths for OptinMonster, TrustPulse, and PushEngage were hit in a CDN supply-chain incident after attackers stole...

Latest development: 15.06.2026 20:37

Awesome Motive remediated the marketing site, migrated it to a new server, and rotated all credentials, including the CDN API key, after attackers exploited a known UpdraftPlus flaw to steal CDN account credentials from a server in its environment and modify JavaScript served from the company's CDN. The company says its application servers, source code, and systems storing OptinMonster and TrustPulse account information were hosted separately and were not breached.

Timeline

  1. 10.08.2026 17:30 1 articles · 13d ago

    Prime Slider script adds an unescaped HTML attribute sink

    Technical Analysis Update

    A March 1 Prime Slider change in BdThemes' code concatenated a field from the remote JSON response directly into an HTML attribute without escaping it, leaving a browser-executed path in the wp-admin banner code and showing the unsafe attribute was introduced by oversight.

    Show sources
  2. 08.08.2026 03:00 4 articles · 16d ago

    Wordfence discloses a BdThemes plugin supply-chain compromise

    Initial Disclosure

    Wordfence disclosed a BdThemes WordPress supply-chain compromise after attackers poisoned the Biggopti promotional API feed, used wp-admin page loads to create rogue administrator accounts and install a webshell on live sites, and caused all seven affected plugins to be temporarily closed pending review.

    Show sources