# WordPress Supply‑Chain Attack Leaves Websites Exposed to Hidden Admins and Backdoor Control

*Tuesday, August 11, 2026 at 6:12 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-08-11T06:12:49.540Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/13940.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers gained write access to data used by seven popular BdThemes WordPress plugins, allowing them to inject poisoned JSON that created rogue admin accounts and web shells on sites that trusted the vendor. The incident shows how a single compromised plugin provider can turn thousands of ordinary websites into potential launchpads for espionage, disinformation or further attacks.

A quiet change in a single software feed has left an unknown number of websites around the world effectively open to remote control. Security researchers have disclosed a supply‑chain attack on BdThemes, a vendor of popular WordPress plugins, in which attackers gained write access to JSON data fetched inside site dashboards and used it to plant backdoors on customer sites. According to technical reporting, seven BdThemes plugins were affected and have since been disabled. The attackers apparently compromised vendor‑hosted infrastructure that delivered configuration and update data to the plugins. By tampering with that JSON stream, they were able to inject malicious code that, when processed by the plugin on a…

---

*Full article available with Hamer Intel Pro — https://hamerintel.com/pricing*
