Not a great month for our favorite Elementor-related plugins...
A supply chain hit has just taken down the BdThemes lineup, disabling popular plugins like Element Pack and Prime Slider on the official WordPress directory. This is not your typical code hack. They did not touch any files on the WordPress servers. Instead, they went upstream and poisoned the remote static JSON feed that pushes promotional banners into the admin dashboard.
___
Element Pack Addons for Elementor, Prime Slider Addons for Elementor, Pixel Gallery Addons for Elementor, Ultimate Post Kit Addons for Elementor, Ultimate Store Kit, Live Copy Paste for Elementor, Smart Admin Assistant.
----
In short, an escaping flaw allowed malicious data from that feed to execute JavaScript whenever an administrator loaded a WordPress admin page. The injected JavaScript could silently create rogue administrators, install a web shell, and establish persistent backdoors. Yeah, that's not good.
Why is this important?
The plugin files themselves did not need to be altered.
Let's let that sink in for a moment...
[link] [comments]