BdThemes Limited A.I CyberSecurity Scoring
BdThemes Limited
Company Information
Website:https://bdthemes.com
Employees number:19
Number of followers:2,879
NAICS:5112
Industry Type:Software Development
Homepage:bdthemes.com
BdThemes Limited Risk Score (AI oriented)
Between 700 and 749
BdThemes LimitedSoftware Development
Updated:
10/08/2026
10/08/2026
731/1000
Moderate
Ba
BdThemes Limited Global Score (TPRM)
xxxx
BdThemes LimitedSoftware Development
Score locked

BdThemes LimitedModerate
Current Score
731Ba (MODERATE)
01000
1 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
750
Cyber Attack
07 Aug 2026 • BdThemes Limited
BdThemes: BdThemes plugins supply-chain hack creates rogue WordPress admins
BdThemes Supply-Chain Attack Compromises 350,000+ WordPress Sites
731
CRITICAL-19
BDT1786400621
BdThemes Supply-Chain Attack Compromises 350,000+ WordPress Sites
A threat actor breached the upstream infrastructure of BdThemes, a developer of premium WordPress plugins, and injected malicious code into a remote JSON feed used by administrative dashboards. The attack, first detected by Wordfence on August 7, exploited a cross-site scripting (XSS) vulnerability in the Biggop Library, a component used to fetch promotional banners from BdThemes’ API.
The flaw, introduced in March 2026, allowed attackers to replace legitimate JSON responses with malicious JavaScript. When executed in an administrator’s browser, the code created rogue admin accounts and installed a webshell (emer-run.php) disguised as a fake plugin for persistence. The attack was stealthy, requiring no user interaction or file modifications, and manipulated database queries to hide the rogue accounts from the WordPress user list.
Wordfence linked the campaign to the same threat actor behind recent supply-chain compromises of Advanced Responsive Video Embedder and OptinMonster, with the earliest signs of activity dating back to June 23. The affected plugins including Element Pack (100,000+ active installs), Prime Slider, Ultimate Post Kit, Pixel Gallery, and Ultimate Store Kit were pulled from WordPress.org on August 8 pending a full review. While two poisoned API endpoints now return clean data, the vulnerability remains unpatched as of the report’s publication.
BdThemes has not issued an official statement, and the total number of compromised sites remains unclear. The developer’s portfolio claims over 350,000 active installations.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
JULY 2026
750
JUNE 2026
750
MAY 2026
750
APRIL 2026
750
MARCH 2026
750
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for BdThemes Limited ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in July 2026 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in June 2026 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in May 2026 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in April 2026 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in March 2026 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in February 2026 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in January 2026 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in December 2025 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in November 2025 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in October 2025 ??
What was BdThemes Limited's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on BdThemes Limited's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with BdThemes Limited ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view BdThemes Limited's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?