supply-chain BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The attack exploited a cross-site scripting (XSS) vulnerability in the vendor’s internal API, leading to th… The Hacker News · Aug 11, 2026 High CVE-2026-18072CVE-2026-64638wordpresssupply-chainxss