WordPress Plugin Vendor BdThemes Hit by Supply Chain Attack, Creating Rogue Admin Accounts
Security researchers have identified a supply chain attack targeting BdThemes, a vendor of popular WordPress plugins, which allowed attackers to create unauthorised administrator accounts on affected websites. In response, WordPress.org's plugins team temporarily disabled downloads of the affected plugins to limit further impact.
What makes this attack notable is its method: according to Wordfence researcher Paolo Tresso, no source code files within the official WordPress.org repository were modified. Instead, attackers poisoned a JSON file used by the plugins, allowing malicious instructions to be executed without triggering typical code-based detection methods. This approach highlights how attackers are finding new ways to compromise trusted software supply chains beyond simply altering source code.
For Australian small businesses using WordPress, this incident is a reminder that even legitimate, well-known plugins can become attack vectors through indirect means such as configuration or data files. Business owners should ensure plugins are kept updated, monitor for unexpected new admin accounts, and remove any plugins that are no longer actively maintained or have been flagged by security researchers.