← Back to Feed
BdThemes plugins supply-chain hack creates rogue WordPress admins
August 10, 2026 · BleepingComputer · Severity: MEDIUM
A threat actor compromised the upstream infrastructure of BdThemes, a WordPress plugin developer, to modify a remote JSON feed. This modification created rogue admin accounts in administrators' browsers, enabling unauthorized access.
Key Takeaways
- Threat actors compromised BdThemes upstream infrastructure to inject malicious code.
- Modified remote JSON feed created rogue admin accounts in WordPress installations.
- Supply-chain attack targeted users of premium WordPress web-design tools.