Skip to content

tagblick

Tuesday, 11 August 2026

Search

Cybersecurity

BdThemes Plugins Compromised in Supply-Chain Attack

BdThemes suffered a supply chain attack that altered how their WordPress plugins function, creating unauthorized admin accounts.

BdThemes Plugins Compromised in Supply-Chain Attack
Photo: purplelime · Openverse · BY-SA

A supply chain attack targeting BdThemes, a provider of premium WordPress plugins, has raised significant cybersecurity concerns. According to BleepingComputer, a threat actor compromised the developer's upstream infrastructure, which led to modifications in a remote JSON feed. This alteration enabled the creation of rogue administrator accounts on affected WordPress sites.

Responding to the threat, The Hacker News reported that the plugins team at WordPress temporarily disabled downloads of BdThemes plugins. Notably, Paolo Tresso from Wordfence stated that unlike typical supply chain attacks, no source code files were altered in the official WordPress.org repository during this incident.