Campaign · Open Source · · 57 days

Vendor-side WordPress compromises seeded rogue admins

Between June and August 2026 the same operators reached WordPress sites through three vendor-side compromises rather than through site vulnerabilities, hitting Awesome Motive's CDN, the ARVE plugin's source, and BdThemes' promotional API feed.

Draws together 3 incidents across 11 packages

Three WordPress supply-chain compromises in the summer of 2026 shared an approach and, according to Wordfence, infrastructure. In each case the attackers did not exploit the victim sites. They compromised something the sites already trusted, and used an administrator's own authenticated session to create a rogue account and install persistence.

The first was Awesome Motive. On June 12, an attacker who had reached the company's marketing server through a known UpdraftPlus vulnerability found a CDN API key there and used it to modify the SDK JavaScript that OptinMonster, TrustPulse, and PushEngage load into more than 1.2 million customer sites. The second, on July 28, was a hardcoded authentication bypass committed into Advanced Responsive Video Embedder, a plugin with about 20,000 installations, by someone with access to the developer's account. The third, disclosed August 8, poisoned the static JSON promotional feed that seven BdThemes plugins render in the dashboard, exploiting an unescaped attribute the vendor had introduced in March.

The payloads converged. All three created administrator accounts through the live admin session, installed a plugin that filters itself out of the admin plugin list, and reported back to a command-and-control host. Wordfence, which analyzed the ARVE and BdThemes cases, said the C2 domain in the BdThemes campaign tied back to the operators behind the other two.

What the group appears to have understood is that vendor-side compromise defeats the standard defenses. In the Awesome Motive and BdThemes cases nothing on the victim's disk changed, so file-integrity scanning saw a clean site, and no plugin update was required to become a victim. Site owners were left auditing user tables and plugin directories rather than version numbers.

Notes

  • The link between the three is Wordfence's statement in the BdThemes analysis that the C2 domain is related to the same threat actors behind the Advanced Responsive Video Embedder and OptinMonster compromises. No public naming of the group exists.
  • The ShapedPlugin compromise recorded at [[shapedplugin]] occurred in the same period and also targeted a vendor distribution pipeline, but no source ties it to these operators, so it is not linked to this campaign.
  • The user figure is dominated by the Awesome Motive installed base. BdThemes install counts were not published and ARVE contributes roughly 20,000.

Incidents in this campaign

  1. Awesome Motive CDN served backdoor JavaScript to 1.2M sites
  2. BdThemes plugins poisoned through the vendor's banner feed
  3. ARVE WordPress plugin shipped a hardcoded admin backdoor

Appendix · Affected packages

optinmonster 2026-06-12 to 2026-06-13
trustpulse-api 2026-06-12 to 2026-06-13
pushengage 2026-06-12 to 2026-06-13
bdthemes-element-pack-lite 2026-06-23 to 2026-08-08
bdthemes-prime-slider-lite 2026-06-23 to 2026-08-08
pixel-gallery 2026-06-23 to 2026-08-08
ultimate-post-kit 2026-06-23 to 2026-08-08
ultimate-store-kit 2026-06-23 to 2026-08-08
live-copy-paste 2026-06-23 to 2026-08-08
smart-admin-assistant 2026-06-23 to 2026-08-08

Samples and hashes sit on each incident page, linked above

References

  1. PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response - Wordfencewordfence.com
  2. Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced - Wordfencewordfence.com
  3. OptinMonster supply chain attack hits 1.2 million sites - Sansecsansec.io

Source record: oss/campaigns/wordpress-admin-persistence-2026/meta.yaml