BdThemes Supply Chain Attack Exploits JSON Vulnerability to Create Rogue WordPress Admins
A supply chain attack on BdThemes' WordPress plugins exploited a JSON vulnerability to inject cross-site scripting (XSS) code, enabling attackers to create rogue administrator accounts and deploy web shells. The attack leveraged compromised cloud storage to deliver payloads, including deterministic credentials and persistence modules, affecting multiple popular plugins.
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads.
"Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
*** END OF TRANSMISSION ***