CyberSecurity News
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
AI summary
A supply chain attack has been discovered affecting BdThemes, a WordPress plugin vendor, leading to the temporary disabling of their plugin downloads by the WordPress plugins team. The attack did not involve modifying any source code files within the official WordPress repository. Instead, the compromise involved poisoning JSON data to create unauthorized WordPress administrators. Researchers at Wordfence have been investigating the incident, with Paolo Tresso noting its unusual nature compared to traditional supply chain attacks. The attack's impact is currently being mitigated by the temporary removal of the affected plugins. The WordPress plugins team has taken this step to prevent further potential damage.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

