CYBERSECURITYTRACKER
TRACKING7,735 stories in this site build1,671 vulnerability news stories in this site build
Permanent story citation

BdThemes plugins supply-chain hack creates rogue WordPress admins

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4179

As cited

Copy frozen at (site build).

breaches incidents

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised BdThemes' upstream infrastructure and manipulated a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack represents a supply-chain compromise affecting users of the company's premium design plugins. The modification allowed attackers to gain administrative access through browsers accessing the poisoned feed.

Why it matters: WordPress administrators using BdThemes plugins need to audit for unauthorized admin accounts immediately and verify the integrity of their sites, as attackers gained high-level access through a trusted vendor's infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised BdThemes' upstream infrastructure and manipulated a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack represents a supply-chain compromise affecting users of the company's premium design plugins. The modification allowed attackers to gain administrative access through browsers accessing the poisoned feed.

Why it matters: WordPress administrators using BdThemes plugins need to audit for unauthorized admin accounts immediately and verify the integrity of their sites, as attackers gained high-level access through a trusted vendor's infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised BdThemes' upstream infrastructure and manipulated a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack represents a supply-chain compromise affecting users of the company's premium design plugins. The modification allowed attackers to gain administrative access through browsers accessing the poisoned feed.

Why it matters: WordPress administrators using BdThemes plugins need to audit for unauthorized admin accounts immediately and verify the integrity of their sites, as attackers gained high-level access through a trusted vendor's infrastructure.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary