Utopia Tech
SecurityAI-assisted1 min read

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

A supply chain attack targeting WordPress plugin vendor BdThemes has been discovered, leading to temporary suspension of their plugin downloads. The attack uniquely manipulated JSON data rather than modifying source code in the official WordPress.org repository, allowing threat actors to create unauthorized administrator accounts.

UT

Utopia Tech

August 11, 2026 · 1 min read

Share

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content