As cited
Copy frozen at (site build).
breaches incidents
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised BdThemes' upstream infrastructure and manipulated a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack represents a supply-chain compromise affecting users of the company's premium design plugins. The modification allowed attackers to gain administrative access through browsers accessing the poisoned feed.
Why it matters: WordPress administrators using BdThemes plugins need to audit for unauthorized admin accounts immediately and verify the integrity of their sites, as attackers gained high-level access through a trusted vendor's infrastructure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised BdThemes' upstream infrastructure and manipulated a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack represents a supply-chain compromise affecting users of the company's premium design plugins. The modification allowed attackers to gain administrative access through browsers accessing the poisoned feed.
Why it matters: WordPress administrators using BdThemes plugins need to audit for unauthorized admin accounts immediately and verify the integrity of their sites, as attackers gained high-level access through a trusted vendor's infrastructure.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
breaches incidents
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised BdThemes' upstream infrastructure and manipulated a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack represents a supply-chain compromise affecting users of the company's premium design plugins. The modification allowed attackers to gain administrative access through browsers accessing the poisoned feed.
Why it matters: WordPress administrators using BdThemes plugins need to audit for unauthorized admin accounts immediately and verify the integrity of their sites, as attackers gained high-level access through a trusted vendor's infrastructure.
- Source published
- First seen by Cybersecurity Tracker