BdThemes plugins compromised, rogue WordPress admins created
TL;DR. BdThemes WordPress plugins were hit by a supply-chain attack, enabling threat actors to create unauthorized admin accounts through a cross-site scripting vulnerability present since March 2026. - Malicious code was injected into a remote JSON feed. - Over 350,000 active installs of BdThemes products are impacted by the vulnerability. - The WordPress Plugins team removed affected products for a security review.
- A supply-chain attack on BdThemes compromised its WordPress plugins, creating rogue admin accounts.
- Attackers exploited a cross-site scripting (XSS) vulnerability via a malicious JSON feed.
- The vulnerability affects over 350,000 active installations and has been present since March 2026.
- WordPress Plugins team removed all BdThemes products from the platform for review.
Sources
- BdThemes plugins supply-chain hack creates rogue WordPress admins — bleepingcomputer.com
- thehackernews.com — thehackernews.com