ATLAS · LIVE
ATLAS INDEX
Δ 24H
ACTIVE SOURCES20
HOTSPOTS20
TIME23:07:39 UTC
← All briefs
HIGHCyber IntelligenceTuesday, August 11, 2026

WordPress Plugin Vendor Hit by JSON-Based Supply Chain Attack

BdThemes compromise bypassed code repository safeguards by poisoning configuration files, creating rogue admin accounts without altering source code.

WordPress has suspended downloads from BdThemes, a plugin vendor serving thousands of sites, after researchers identified a supply chain attack that created unauthorized administrator accounts without modifying tracked source code.

Wordfence researcher Paolo Tresso reported the intrusion departed from conventional supply chain methods. Rather than altering code files monitored within the official WordPress.org repository, attackers poisoned JSON configuration data. This approach allowed the creation of rogue admin credentials while evading repository integrity checks designed to flag unauthorized code changes.

The technique exploits a structural gap in how WordPress validates plugin packages. Source code undergoes version control and review, but ancillary files—including JSON manifests—may receive less scrutiny. By embedding malicious directives in these files, attackers gained administrative access to sites running affected BdThemes products.

The rest of this brief is inside the platform

Continue reading. Free.

A free Atlas account unlocks the full briefing, the co-analyst, daily delivery to your inbox, and a sector-personalised feed.

Full brief
Implications, sources, methodology
Co-Analyst
Ask follow-ups on every brief
Sector feed
Briefs filtered to what matters to you
Implications
  • 01WordPress site operators using BdThemes plugins face potential unauthorized admin access until patches deploy.
  • 02Plugin vendors must extend integrity monitoring beyond source code to configuration and metadata files.
  • 03WordPress.org may revise repository validation protocols to cover non-code attack vectors.
Source
The Hacker News
https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html
Brief is editorial commentary by Atlas Intelligence based on the cited public reporting. Atlas does not reproduce source text. Verify primary source before action.
#supply chain#wordpress#plugin security#json poisoning#bdthemes#wordfence
Related Briefs