BdThemes plugins supply-chain hack creates rogue WordPress admins

BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised BdThemes’ upstream infrastructure and poisoned a remote JSON feed, using the attack to create rogue administrator accounts on WordPress sites. The incident affected several BdThemes plugins, including Element Pack, and has been linked by researchers to a broader supply-chain campaign. #BdThemes #ElementPack #Wordfence #Sigmative #Biggop Library

Keypoints

  • A threat actor compromised BdThemes’ upstream infrastructure.
  • The attacker modified a remote JSON feed used by admin browser components.
  • The exploit created rogue administrator accounts on impacted WordPress sites.
  • Defiant linked the activity to a broader supply-chain campaign.
  • WordPress.org removed BdThemes plugins pending a full review.

Read More: https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/