Cybersecurity researchers uncovered a supply chain compromise at BdThemes that poisoned remote JSON data used by several WordPress plugins, leading WordPress to temporarily disable downloads pending review. The attack leveraged the Biggopti component to trigger XSS in wp-admin, enabling rogue administrator creation, web shell deployment, and persistent backdoor access. #BdThemes #WordPress #Biggopti #ia-cdncom #w2js #xjs
Keypoints
- WordPress disabled downloads for several BdThemes plugins after a supply chain compromise.
- Attackers poisoned a remote JSON stream instead of modifying files in the WordPress.org repository.
- The Biggopti component contained an XSS flaw in its JSON response parsing code.
- Injected scripts ran in wp-admin and created rogue administrator accounts and a web shell.
- Malicious payloads also installed persistence modules and used deterministic admin credentials.
Read More: https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html