This is a useful WordPress supply chain case because the attackers apparently never needed to publish a malicious plugin update.
Wordfence says several BdThemes plugins contained an internal component called Biggopti that fetched promotional banner data from an API-backed DigitalOcean Spaces bucket and rendered it inside the WordPress admin interface.
The problem was an XSS issue in how one JSON parameter, display_id, was handled.
Attackers reportedly gained write access to the upstream bucket and replaced legitimate JSON responses with malicious ones.
Because the vulnerable component loaded inside wp-admin, the injected script could execute silently whenever a logged-in administrator opened an affected admin page.
That gave the attackers the privilege context they needed without modifying the plugin files themselves.
The main JavaScript payload could:
create a rogue WordPress administrator through the REST API,
download and upload a fake plugin,
deploy a PHP web shell called emer-run.php,
and install persistence into the mu-plugins directory.
The persistence layer is particularly interesting.
One module created a “magic login” backdoor using a URL parameter that could grant unauthenticated admin access. Another hooked WordPress database queries to hide malicious users from the admin user list and adjust the displayed account count so the rogue users were less obvious.
Wordfence also found an alternate payload that generated deterministic admin credentials from the hostname of the compromised site.
That means the username and password don't need to be stored centrally by the attacker. They can be recreated mathematically for a given domain.
From an incident-response perspective, that is actually helpful because defenders can calculate what malicious account names should exist on a suspected site and hunt for them directly.
The plugin with the largest stated exposure is Element Pack Addons for Elementor, which has more than 100,000 active installs. Several other BdThemes plugins were also temporarily closed in the WordPress directory for review.
One thing I find notable here is the trust boundary.
Most supply chain discussions focus on malicious package releases, compromised repositories, or backdoored updates. Here, the installed plugin code could remain unchanged while a remote data source it trusted became the actual delivery mechanism.
For plugin ecosystems, should any remote JSON or promotional content rendered in a privileged admin context be treated as executable supply chain input and subjected to stronger integrity controls?
Source: r/TechNadu · by /u/technadu