A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators’ browsers to create rogue admin accounts.
Starting Saturday, the affected BdThemes products were no longer available for download after the WordPress Plugins team closed all of them pending a full review.
BdThemes provides premium WordPress plugins, including Element Pack, Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit.
Its flagship free Element Pack plugin alone currently shows more than 100,000 active installations on WordPress.org, while the developer advertises a portfolio with over 350,000 active installs.
WordPress security firm Defiant started seeing attacks through its Wordfence web application firewall (WAF) on August 7.







