BdThemes plugins supply-chain hack creates rogue WordPress admins
BdThemes plugins were hit by a supply-chain attack that resulted in the creation of rogue WordPress admin accounts. The attack, reported by BleepingComputer, involved compromising the plugin supply chain, which allowed attackers to inject malicious code that created unauthorized admin users on affected WordPress sites. This gave attackers full control over the sites, potentially leading to further compromise. The incident underscores the risks associated with third-party plugins and the importance of supply chain security in the WordPress ecosystem. BleepingComputer's report did not specify which BdThemes plugins were affected or the number of sites impacted, but the creation of rogue admins is a critical security issue that could lead to data breaches, defacement, or other malicious activities.
WordPress site owners using BdThemes plugins face unauthorized admin access, risking full site compromise.