WordPress Supply-Chain Breach Exposes Millions of Sites to Rogue Admin Takeovers
Attackers compromised several popular BdThemes WordPress plugins by poisoning a JSON file used inside site dashboards, enabling silent creation of rogue admin accounts and web shells. The supply-chain breach turns routine plugin updates into an intrusion vector, raising fresh questions for small businesses, media outlets, and governments that rely on WordPress for critical web infrastructure.
A supply-chain attack on multiple popular WordPress plugins has turned a routine administrative function into a potential backdoor, exposing millions of websites to silent takeover and long-term compromise. For site owners who assumed that updating plugins inside their dashboard was a basic security best practice, the incident is an uncomfortable reminder that trusted components can be weaponized upstream. Security researchers disclosed that seven plugins maintained by BdThemes were compromised after attackers gained write access to a JSON file hosted on vendor-controlled infrastructure. That file was fetched by the affected plugins from within the WordPress administration panel. By poisoning the data delivered to sites that installed the plugins, the attackers were…
Pro features include
- 60+ analytical tools across markets and intelligence
- Custom alerts, watchlists, and AOI monitoring
- Daily Pro brief at 6 PM ET — 12 hours before free tier
- Conflict deep dives and premium research products