BdThemes plugins supply-chain hack creates rogue WordPress admins

Summary

A threat actor gained access to the development infrastructure of BdThemes, a provider of WordPress plugins, and altered a remote JSON feed. This manipulation allowed them to create unauthorized administrator accounts on websites using BdThemes' plugins.

IFF Assessment

FOE

The compromise of a plugin developer's infrastructure to inject malicious code that creates rogue administrators is a direct attack on website security.

Defender Context

This incident highlights the risks associated with supply chain attacks targeting software developers. Defenders should be aware of the potential for vulnerabilities to be introduced through third-party plugins and consider implementing stricter vetting processes for software dependencies.

Read Full Story →