
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response
A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the incident on August 7, 2026, after discovering that attackers had poisoned a remote promotional API feed used by several popular BdThemes plugins. The affected plugins include Element Pack […]
The post New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response appeared first on Cyber Security News.