BdThemes plugins compromised, rogue WordPress admins created

TL;DR. BdThemes WordPress plugins were hit by a supply-chain attack, enabling threat actors to create unauthorized admin accounts through a cross-site scripting vulnerability present since March 2026. - Malicious code was injected into a remote JSON feed. - Over 350,000 active installs of BdThemes products are impacted by the vulnerability. - The WordPress Plugins team removed affected products for a security review.

Sources

Back to QLANKR News