WordPress News: Supply Chain Attacks and Critical Patches (Week of 11 August 2026)

This week's WordPress news is a good reminder that not every attack needs to touch a single file on your server. A plugin vendor's cloud storage got compromised and used to inject malicious code straight into thousands of WordPress dashboards, WordPress core shipped a security release worth installing without delay, and one AI plugin has a critical, unpatched hole in it. WooCommerce store owners also get a modest, welcome performance update. Let's go through what actually matters.
If you run BdThemes or Elementor add-ons, check your admin user list today
Wordfence reported that BdThemes, the company behind popular Elementor add-ons including Element Pack, Prime Slider, Pixel Gallery, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste, and Smart Admin Assistant, had its cloud storage compromised. Attackers didn't touch a single plugin file. Instead, they poisoned a promotional banner feed that these plugins pull into the WordPress dashboard, using it to inject a script that creates rogue administrator accounts and installs a hidden webshell. It's the WordPress equivalent of someone slipping a tracking device onto a ship without anyone opening the cargo hold: nothing on board looks different, but the mission is already compromised. The affected plugins have been pulled from the WordPress.org directory while the investigation continues, and the vendor's poisoned feed was cleaned as of 8 August.
What this means for you: if any of those seven plugins are installed on your site, don't wait for an update, there may not be a file-based fix to install. Check your WordPress users list for accounts you don't recognise, especially ones using a wordpress.org email address or a username starting with "bd_". If you find anything unfamiliar, treat the site as compromised: rotate your secret keys, invalidate all sessions, and get a proper cleanup done. Our complete recovery guide walks through the process, and our security best practices guide is worth a read regardless of whether you were hit.
Update to WordPress 7.0.3 as soon as you can
WordPress.org released version 7.0.3 on 6 August, a dedicated security release. It fixes a dozen issues, including a pre-authentication cross-site scripting bug on the login screen that could lead to PHP code execution, several stored XSS issues reachable by Contributor-level accounts, a privilege escalation bug on multisite networks, and a server-side request forgery flaw. None of these require you to do anything clever. They require you to update.
What this means for you: if your site auto-updates for minor releases, you're likely already patched, but it's worth confirming in Dashboard → Updates. If you've disabled automatic updates for any reason, update manually this week. This is exactly the kind of release a maintenance plan takes off your plate automatically, so you're not the one who has to remember.
If you use the AI Copilot Content Generator plugin, remove it now
Wordfence disclosed a critical, unauthenticated privilege escalation vulnerability (CVSS 9.8) in AI Copilot – Content Generator, affecting all versions up to 1.5.6. Any site displaying the plugin's chatbot or form shortcode on a public page leaks the security token needed to exploit it, letting an attacker create a full administrator account with no login required. As of this writing, there is no patch available.
What this means for you: if you're running this plugin, especially with its public-facing chatbot or form enabled, the safest move is to deactivate and remove it until a fixed version ships. Details on the fix timeline are still emerging, so don't wait around hoping for a quiet patch. This is also a fair moment to be cautious about any AI content or chatbot plugin you didn't vet carefully before installing: convenient features and broad, unauthenticated access points don't mix well.
WooCommerce 11.0 brings faster product pages and better analytics
WooCommerce released version 11.0 on 5 August. The headline changes are performance-focused: an Orders-screen optimisation for large stores, and a product object caching experiment that makes variable product pages load 9 to 12 percent faster, with bundle products processing up to 12 percent faster at checkout. Analytics also got more trustworthy, refunds now count in the month they happened, and session counts filter out bots so your conversion rates stop looking artificially low.
What this means for you: if you run a WooCommerce store, update when convenient and expect small, positive changes rather than anything disruptive. If your developer built custom sales reporting, flag the refund-period change to them so their numbers stay consistent. If checkout speed on a heavier catalogue has been bothering you for a while, this release, combined with a general performance review, is worth revisiting. Our guide on why your WordPress site might be running slow is a good place to start if speed has been a recurring complaint.
Wrapping up
The theme this week is straightforward: two serious security stories worth acting on, one solid core release, and a genuinely useful WooCommerce update. None of it requires panic, but the BdThemes situation and the AI Copilot plugin both deserve a few minutes of your attention today rather than next month. A maintenance plan handles exactly this kind of monitoring and patching automatically, so these updates happen before they become emergencies.
May the Code Be With You.
Wynand Holtzhausen
Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.


