BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Read full story on The Hacker News
Share
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
AI disclosure

Summary

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.