Skip to content
archivesupply chain · 11 Aug 2026 · 05:48 UTC

BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

last 60 dispatches · spectrum

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

Sources · 2

outlets reporting the same story — pick one to read

grounded ✓primary source ↗

loading threat intel…

Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected