Ravie LakshmananAug 11, 2026Supply Chain Attack / Vulnerability

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads.

"Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said. "Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component."

The list of affected plugins is below -

Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons [bdthemes-element-pack-lite] - 100,000+ active installs