
BDThemes WordPress Supply Chain Attack Creates Rogue Admins and Deploys Webshells
A supply chain compromise has hit BdThemes, a popular WordPress plugin vendor, allowing attackers to silently create rogue administrator accounts and install webshells on affected sites without modifying a single line of plugin code. The Wordfence Team was alerted to the campaign on August 7, 2026, and all impacted plugins have since been pulled from […]
The post BDThemes WordPress Supply Chain Attack Creates Rogue Admins and Deploys Webshells appeared first on Cyber Security News.