ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
HIGH Open Source

BdThemes WordPress supply-chain incident creates rogue admin accounts

Source headline: BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Threat level High
Signal strength 75/100
Source confidence 1 source
Published 3 hours ago

Intelligence Summary

A supply-chain compromise has affected the BdThemes WordPress plugin vendor. Researchers say attackers poisoned the delivery contents to create rogue WordPress administrators. Wordfence reports that no source code files were modified inside the official WordPress.org repository. The plugins team temporarily disabled BdThemes downloads as a containment measure. Site owners using affected plugins should update from fixed releases and review admin account activity.

Recommended Action

Review affected assets, schedule urgent remediation, and monitor related indicators.

Topics

#supply-chain #privilege-escalation #wordpress #admin-account-takeover #plugin-vendor
Original reporting The Hacker News BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Open original source