A threat actor compromised BdThemes' infrastructure and modified a remote JSON feed to create unauthorized admin accounts on affected WordPress sites. The attack leveraged the company's premium web-design plugin distribution system.
BdThemes, a WordPress plugin developer, fell victim to a supply-chain attack that gave attackers administrative access to customer installations. The threat actor gained access to the company's upstream infrastructure and manipulated a JSON feed delivered to site administrators' browsers.
By injecting malicious code into the feed, attackers created rogue admin accounts on WordPress sites running BdThemes plugins. This method bypassed typical installation processes and gave adversaries persistent access to affected websites.
The attack highlights risks in WordPress plugin ecosystems, where compromised developer infrastructure can impact thousands of downstream users. BdThemes has not yet disclosed the full scope of affected sites or provided detailed remediation guidance. WordPress administrators using BdThemes plugins should audit their user accounts and access logs for unauthorized activity, update plugins immediately, and consider resetting admin credentials.
HackerOne, the bug bounty platform, has come under criticism following recent policy shifts and operational decisions that have impacted its security researcher community.
Simply deleting files from old USB drives before disposal provides minimal data protection. Experts warn that deleted data can be recovered with basic tools, making proper wiping essential.
CISA has confirmed that ransomware groups are actively exploiting two recently patched vulnerabilities in SonicWall SMA1000 devices, including a critical server-side request forgery flaw.