BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The attack exploited a cross-site scripting (XSS) vulnerability in the vendor’s internal API, leading to the injection of malicious code and the establishment of persistent administrative access. This campaign is linked to previous supply chain attacks targeting Advanced Responsive Video Embedder and OptinMonster, highlighting a pattern of coordinated efforts to compromise WordPress environments.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
