news.mlab.sh
1 result
supply-chain

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

A supply chain attack originating from BdThemes, a WordPress plugin vendor, has been discovered, allowing threat actors to create rogue administrator accounts and install malicious plugins across WordPress sites. The attack exploited a cross-site scripting (XSS) vulnerability in the vendor’s internal API, leading to th…

The Hacker News · Aug 11, 2026 High