ShellCodeX Intelligence Brief
HIGH
Open Source
BdThemes WordPress supply-chain incident creates rogue admin accounts
Source headline: BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Threat level
High
Signal strength
75/100
Source confidence
1 source
Published
3 hours ago
Intelligence Summary
A supply-chain compromise has affected the BdThemes WordPress plugin vendor. Researchers say attackers poisoned the delivery contents to create rogue WordPress administrators. Wordfence reports that no source code files were modified inside the official WordPress.org repository. The plugins team temporarily disabled BdThemes downloads as a containment measure. Site owners using affected plugins should update from fixed releases and review admin account activity.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.
Topics
Original reporting
The Hacker News
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Open original source