← Back to Feed

BdThemes plugins supply-chain hack creates rogue WordPress admins

August 10, 2026 · BleepingComputer · Severity: MEDIUM

A threat actor compromised the upstream infrastructure of BdThemes, a WordPress plugin developer, to modify a remote JSON feed. This modification created rogue admin accounts in administrators' browsers, enabling unauthorized access.

Key Takeaways

  • Threat actors compromised BdThemes upstream infrastructure to inject malicious code.
  • Modified remote JSON feed created rogue admin accounts in WordPress installations.
  • Supply-chain attack targeted users of premium WordPress web-design tools.
☕ Buy a Coffee