BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
A supply chain attack on WordPress plugin vendor BdThemes poisoned JSON data to create rogue admin accounts, prompting WordPress to temporarily disable the plugins. Unlike typical attacks, no source code was altered in the official repository.
BdThemes, a WordPress plugin vendor, suffered a supply chain attack that poisoned JSON files to create rogue admin accounts. WordPress’s plugins team temporarily disabled downloads of the affected plugins. Unlike typical supply chain attacks, no source code was modified in the official WordPress.org repository, according to Wordfence researcher Paolo Tresso. The compromise allowed attackers to inject malicious JSON, granting unauthorized admin access to sites using the plugins.