CyberNews
← Back to dashboard
NEWS The Hacker News

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Aug 11, 2026, 05:48 AM · by The Hacker News

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

Supply chain compromises are especially dangerous because trust in a vendor’s distribution channel is abused to reach a much wider set of victims than a direct attack ever could.

Beyond patching, organizations should inventory exposed services, disable unused functionality, and require multi-factor authentication wherever it can be deployed.

Source: The Hacker News