A threat actor compromised BdThemes’ upstream infrastructure and poisoned a remote JSON feed, using the attack to create rogue administrator accounts on WordPress sites. The incident affected several BdThemes plugins, including Element Pack, and has been linked by researchers to a broader supply-chain campaign. #BdThemes #ElementPack #Wordfence #Sigmative #Biggop Library
Keypoints
- A threat actor compromised BdThemes’ upstream infrastructure.
- The attacker modified a remote JSON feed used by admin browser components.
- The exploit created rogue administrator accounts on impacted WordPress sites.
- Defiant linked the activity to a broader supply-chain campaign.
- WordPress.org removed BdThemes plugins pending a full review.