Published: · Region: Global · Category: cyber

WordPress Supply‑Chain Backdoor Puts Thousands of Sites and Users at Silent Risk

Attackers gained write access to data used by seven popular BdThemes WordPress plugins, poisoning JSON files to create rogue admin accounts and web shells on sites that installed updates. The compromise shows how a quiet supply‑chain breach in a single plugin vendor can cascade across thousands of websites and the users who trust them.

A stealthy hack on a cluster of popular WordPress plugins has turned routine updates into a vehicle for website takeovers, underscoring how vulnerable the internet’s software supply chain remains even for widely used tools. Security researchers have disclosed that seven plugins developed by BdThemes were effectively weaponized after attackers obtained write access to vendor‑hosted data fetched inside WordPress admin panels. By poisoning JSON configuration files that the plugins relied on, the intruders were able to inject backdoors into sites that used the affected add‑ons, creating unauthorized administrator accounts and planting web shells for remote control. The compromised plugins have since been disabled, but not before code shipped out through legitimate…

Pro features include

  • 60+ analytical tools across markets and intelligence
  • Custom alerts, watchlists, and AOI monitoring
  • Daily Pro brief at 6 PM ET — 12 hours before free tier
  • Conflict deep dives and premium research products