Rejuvenate IT Logo

Seven WordPress plugins were hijacked to create hidden admin accounts – how to check your site

Website security firm Wordfence published a warning on 8 August about a supply-chain attack on BdThemes, whose add-ons for the Elementor page builder are installed on hundreds of thousands of WordPress sites. What makes this one worth your attention is how quietly it worked.

No plugin file was ever changed. Instead, attackers gained write access to BdThemes’ own cloud storage and poisoned a small data feed that fills a promotional banner inside the WordPress dashboard. A coding flaw added in March meant that poisoned data ran as JavaScript in the browser of anyone signed in as an administrator, on every dashboard page they opened.

From there the script created a hidden administrator account, uploaded a webshell and reported back to the attackers. Wordfence names seven affected plugins: Element Pack, Prime Slider, Pixel Gallery, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste and Smart Admin Assistant. BleepingComputer reports that Element Pack alone is active on more than 100,000 sites. The campaign may have been live since 23 June; the plugins were pulled from the WordPress directory on 7 August, and the poisoned feed was cleaned the following day.

Who this affects

You are in scope if your site runs WordPress with Elementor and any of those seven add-ons, and anyone signed into the dashboard between late June and 7 August. Nobody had to click a bad link or install an update. Signing in was enough.

Nothing changed on disk, so a normal file scan comes back clean. Wordfence also found the attackers installed a module to keep the rogue account out of the user list you would normally check. “The site looks fine” is not evidence here. If you do not use Elementor or these plugins, there is nothing for you to do.

What to do this week

  • Check your administrators properly. Look for accounts you do not recognise, usernames beginning bd_ followed by six characters, or any account using a @wordpress.org or @developer.wordpress.org email address. Because they may be hidden from the user screen, this needs checking at database level.
  • Look for the files left behind. Wordfence lists a webshell named emer-run.php, plus must-use plugins called class-wp-token-validate.php, wp-cache-optimizer.php and class-wp-query-*.php.
  • Check the database options table for fz_emer_login_tokens and fz_emer_done_v1.
  • Do not simply update and move on. The underlying flaw was still unpatched when Wordfence published, and the plugins were withdrawn from the directory pending review.
  • If you find anything, treat it as a full compromise. Reset every administrator password, rotate your security keys, and have the site cleaned properly rather than deleting the one file you happened to spot.

If you would rather someone else checked

This is a genuinely hard one to spot from the outside, because the site looks and behaves exactly as it did last week. If you are not sure whether your site uses these plugins, or you would like someone to work through the checks above for you, that is part of what our website maintenance and hosting security cover, with round-the-clock monitoring behind them so a hidden account does not sit there for weeks.

Call us on 01202 237 273 or book a call.