
BdThemes Plugin Supply Chain Attack: WordPress Temporarily Closes Affected Extensions
Wordfence discovers a supply chain compromise in BdThemes plugins via poisoned API response. All affected plugins are temporarily closed pending investigation.
On August 7, 2026, the Wordfence Threat Intelligence Team was alerted to a supply chain compromise affecting BdThemes, a company that develops plugins for WordPress, the widely used website-building platform. These plugins are hosted on the official WordPress plugins directory, which is the primary source for adding functionality to WordPress sites. In response, all affected plugins have been temporarily closed, meaning they are no longer available for download, pending a comprehensive inspection and ongoing investigation by the WordPress Plugins team.
The attack is believed to have been carried out through a poisoned API response. To understand this, it helps to know what an API is. An application programming interface (API) is a set of rules that allows different software programs to talk to each other. In the context of plugin updates, a plugin on a website may contact the vendor's server to check for and download updates. If that server has been compromised, it can send back a malicious response, which is a poisoned API response. This response could contain code or instructions that compromise the website.
This type of attack is known as a supply chain compromise because the compromise happens upstream, at the vendor, before the malicious code reaches the end user. It is particularly dangerous because the plugin is developed by a trusted party, and website owners expect that updates are safe. A supply chain attack can affect many websites at once, because the same vendor's plugins are used across the internet.
For website owners using BdThemes plugins, the temporary closure is a warning. The plugins are no longer being updated, which leaves any existing installations vulnerable. Even if you have not yet updated to a malicious version, your site could be at risk depending on the nature of the compromise. The investigation is ongoing, so more information may emerge. In the meantime, it is prudent to take action to protect your site.
First, identify which plugins you have installed from BdThemes. Common examples include Element Pack and its variations, but there may be others. You can check your WordPress admin dashboard under Plugins. Once you know what you have, watch for news from WordPress and Wordfence about the investigation. Since the plugins are closed, you will not automatically receive fixes, so you must actively seek out information.
If you have backups, ensure they are current. A backup is a snapshot of your website that you can restore if something goes wrong. In this case, if your site is compromised, you can revert to a previous state. Additionally, monitor your website for suspicious behavior, such as unexpected redirects to unknown sites, new admin users you do not recognize, or unexplained changes in your site's files. If you see any of these signs, disable the affected plugin immediately.
Consider using a security service that can detect and block malicious activity. For instance, AEU Hosting provides managed WordPress hosting with end to end security, which includes monitoring and support to help safeguard your website. By relying on a hosting provider that prioritizes security, you reduce the burden of manually watching for vulnerabilities and can focus on your business.
In the meantime, stay vigilant and follow official advisories. The WordPress team and security researchers like Wordfence are working to resolve the issue. Your best defense is awareness and prompt action.
How to Protect Yourself
- Check your WordPress site for any installed BdThemes plugins by going to the Plugins page in your dashboard.
- Keep complete backups of your website so you can restore it if it is compromised.
- Monitor your website for unusual behavior like redirects, new admin accounts, or unexpected changes.
- If you use a BdThemes plugin, consider temporarily disabling it until the investigation is complete.
- Follow official WordPress and Wordfence advisories for updates on this investigation.