BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Image for article BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
News Source : Internet

News Summary

  • Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes.
  • The issue, per the WordPress security company, is rooted in an internal component called Biggopti that's shipped along with the plugins.
  • Users visiting the listings for each of the aforementioned plugins on the WordPress plugins directory are displayed the message that they have been closed as of either August 7 or 8, 2026.
  • The vulnerability is rated 5.4 on the CVSS scoring system, indicating medium severity.

Must read Articles