🔥 この記事の詳細
2026-08-11 更新
C
月内に

WordPressプラグインベンダーであるBdThemesのサプライチェーン攻撃

脆弱性🌐 英語ソース
🖥️ 製品WordPress
📅 2026-08-11📰 hackernews
📌 一言でいうと
WordPressプラグインベンダーであるBdThemesのサプライチェーン攻撃が判明しました。攻撃者は公式リポジトリのソースコードではなく、管理画面のプロモーションバナーが取得する外部JSONデータを汚染し、不正な管理者アカウントを作成させる手法を用いています。影響を受けるプラグインにはElement Pack Addons for Elementorなどが含まれており、WordPressチームは一時的にダウンロードを停止しています。
🔍該当判定
  • WordPressで『Element Pack Addons for Elementor』を利用している
  • WordPressで『Live Copy Paste for Elementor』を利用している
  • WordPressで『Pixel Gallery Addons for Elementor』を利用している
  • WordPressで『Prime Slider Addons for Elementor』を利用している
上記いずれにも該当しない → 静観でOK
該当時の対応
影響を受けるプラグイン(Element Pack Addons for Elementor等)をインストールしている場合は、速やかに管理画面のユーザーリストを確認し、身に覚えのない管理者アカウントが作成されていないかチェックしてください。また、ベンダーからの修正版リリースを待ち、最新バージョンへ更新してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】BdThemes製WordPressプラグインのサプライチェーン攻撃への対応について

お疲れさまです。BdThemes製プラグインにおけるサプライチェーン攻撃に関する情報共有です。

■ 概要
攻撃者がプラグインの管理画面に表示されるプロモーションバナーが参照する外部JSONデータを汚染し、サイトに不正な管理者アカウントを自動作成させる攻撃が確認されました。ソースコード自体の改ざんではなく、外部データストリームを悪用した巧妙な手法です。

■ 影響範囲
- Element Pack Addons for Elementor [bdthemes-element-pack-lite]
- Live Copy Paste for Elementor [live-copy-paste]
- Pixel Gallery Addons for Elementor [pixel-gallery]
- Prime Slider Addons for Elementor

■ 対応手順
1. 自社管理サイトで上記プラグインが利用されているか確認する。
2. 利用している場合、WordPress管理画面の「ユーザー」一覧を確認し、心当たりのない管理者権限アカウントが存在しないか調査する。
3. 不正アカウントを発見した場合は直ちに削除し、パスワードの変更およびセキュリティ監査を実施する。
4. WordPress公式リポジトリでのダウンロード再開および修正版のリリースを確認し、速やかに更新を適用する。

■ 参考情報
- Wordfence / WordPress.org プラグインチーム通知

対応優先度: 高
対応期限: 至急
Subject: [Security Alert] Supply Chain Attack on BdThemes WordPress Plugins

Dear IT/Security Team,

We are sharing information regarding a supply chain compromise affecting plugins from the vendor BdThemes.

■ Overview
Threat actors have poisoned a static remote JSON data stream fetched by administrative promotional banners in several BdThemes plugins. This allows the attackers to create rogue administrator accounts on affected WordPress sites without modifying the source code within the official WordPress.org repository.

■ Affected Products
- Element Pack Addons for Elementor [bdthemes-element-pack-lite]
- Live Copy Paste for Elementor [live-copy-paste]
- Pixel Gallery Addons for Elementor [pixel-gallery]
- Prime Slider Addons for Elementor

■ Action Plan
1. Identify if any of the aforementioned plugins are installed on company-managed WordPress sites.
2. Review the user list in the WordPress admin dashboard for any unauthorized administrator accounts.
3. If rogue accounts are found, delete them immediately and perform a full security audit of the site.
4. Monitor for official updates and apply patches as soon as they are available from the vendor/WordPress repository.

■ Reference
- Wordfence / WordPress.org Plugins Team

Priority: High
Deadline: Immediate