WordPress Plugin Vendor Hit by JSON-Based Supply Chain Attack
BdThemes compromise bypassed code repository safeguards by poisoning configuration files, creating rogue admin accounts without altering source code.
WordPress has suspended downloads from BdThemes, a plugin vendor serving thousands of sites, after researchers identified a supply chain attack that created unauthorized administrator accounts without modifying tracked source code.
Wordfence researcher Paolo Tresso reported the intrusion departed from conventional supply chain methods. Rather than altering code files monitored within the official WordPress.org repository, attackers poisoned JSON configuration data. This approach allowed the creation of rogue admin credentials while evading repository integrity checks designed to flag unauthorized code changes.
The technique exploits a structural gap in how WordPress validates plugin packages. Source code undergoes version control and review, but ancillary files—including JSON manifests—may receive less scrutiny. By embedding malicious directives in these files, attackers gained administrative access to sites running affected BdThemes products.
- 01WordPress site operators using BdThemes plugins face potential unauthorized admin access until patches deploy.
- 02Plugin vendors must extend integrity monitoring beyond source code to configuration and metadata files.
- 03WordPress.org may revise repository validation protocols to cover non-code attack vectors.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.