CyberNews
← Back to dashboard
NEWS The Hacker News

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins - The Hacker News

Aug 11, 2026, 05:48 AM · by The Hacker News

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads.

"Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said. "Instead, threat actors poisoned a static remote JSON data stream fetched by an administrative promotional banner component."

Users visiting the listings for each of the aforementioned plugins on the WordPress plugins directory are displayed the message that they have been closed as of either August 7 or 8, 2026, and are not available for download pending a "full review."

The issue, per the WordPress security company, is rooted in an internal component called Biggopti that's shipped along with the plugins. The system is designed to pull promotional banners from their API server and render them in the WordPress admin dashboard by fetching relevant JSON files from a DigitalOcean Spaces bucket.

Source: The Hacker News