BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Overview
Cybersecurity researchers have identified a supply chain attack affecting BdThemes, a vendor known for its WordPress plugins. This incident has led to the temporary suspension of plugin downloads from the official WordPress repository. According to Wordfence researcher Paolo Tresso, the attack is notable because it did not involve any direct modifications to the source code within the repository. Instead, attackers exploited the system to create unauthorized administrative accounts for WordPress sites using affected plugins. This could allow unauthorized access to numerous WordPress installations, raising serious concerns for users relying on these plugins. WordPress site owners should remain vigilant and consider disabling affected plugins until further notice.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: BdThemes WordPress plugins
- Action Required: Temporarily disable downloads of affected plugins; users should consider disabling these plugins on their sites.
- Timeline: Newly disclosed
Original Article Summary
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
Impact
BdThemes WordPress plugins
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Temporarily disable downloads of affected plugins; users should consider disabling these plugins on their sites.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Malware.