Poisoned JSON stream plants rogue admins in WordPress shops

Poisoned JSON stream plants rogue admins in WordPress shops.

CSBadmin
2 Min Read

Administrators running BdThemes plugins should check for unexpected admin users: WordPress has temporarily disabled downloads of several of the vendor’s plugins after researchers found a supply chain compromise that poisons a remote JSON stream.

Wordfence researcher Paolo Tresso documented the issue, noting that no source code files were modified in the official WordPress.org repository. Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component called Biggopti that ships with the plugins.

That component fetches promotional banner JSON from the vendor’s API server and renders the results inside the wp-admin dashboard by pulling files from a DigitalOcean Spaces bucket. The parsing code mishandles the “display_id” parameter coming from the Sigmative API, leaving a cross-site scripting hole in the JSON response handling due to weak client-side escaping. Anyone able to take over the API can plant web scripts that fire on each page visit.

The script fires on each wp-admin page load, so the injected code runs silently in the browser of any logged-in administrator. The plugins directory shows the affected plugins closed as of August 7 or 8, pending a full review, including Element Pack Addons for Elementor with over 100,000 active installs, Live Copy Paste for Elementor, Pixel Gallery Addons, Prime Slider Addons, Smart Admin Assistant, Ultimate Post Kit, and Ultimate Store Kit.

Administrators running any of these plugins should review recent changes to user roles, rotate credentials for accounts with elevated access, and watch for unexpected administrator accounts while the review is underway.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.