Threat Intelligence

WordPress Plugin Vendor BdThemes Hit by Supply Chain Attack, Creating Rogue Admin Accounts

The Hacker News · 11 Aug 2026
Key Takeaway Regularly audit your WordPress admin accounts and plugin list, and remove or update any flagged software immediately to reduce exposure to supply chain attacks.

Security researchers have identified a supply chain attack targeting BdThemes, a vendor of popular WordPress plugins, which allowed attackers to create unauthorised administrator accounts on affected websites. In response, WordPress.org's plugins team temporarily disabled downloads of the affected plugins to limit further impact.

What makes this attack notable is its method: according to Wordfence researcher Paolo Tresso, no source code files within the official WordPress.org repository were modified. Instead, attackers poisoned a JSON file used by the plugins, allowing malicious instructions to be executed without triggering typical code-based detection methods. This approach highlights how attackers are finding new ways to compromise trusted software supply chains beyond simply altering source code.

For Australian small businesses using WordPress, this incident is a reminder that even legitimate, well-known plugins can become attack vectors through indirect means such as configuration or data files. Business owners should ensure plugins are kept updated, monitor for unexpected new admin accounts, and remove any plugins that are no longer actively maintained or have been flagged by security researchers.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.