Login
← All news

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

The Hacker News Security WordPress

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

Read the full story on The Hacker News https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html
Most WordPress sites are compromised through something ordinary: an unpatched plugin, an abandoned theme, an account without two-factor. If you would rather updates and backups simply happened, CrockyHost hosting does them for you.