BdThemes Supply Chain Attack Creates Rogue WordPress Admins

·
Listen to this article~4 min
BdThemes Supply Chain Attack Creates Rogue WordPress Admins

Wordfence researchers reveal a supply chain attack on BdThemes WordPress plugins that poisoned JSON files to create rogue admin accounts, forcing WordPress.org to disable downloads.

Cybersecurity researchers have uncovered a supply chain attack targeting BdThemes, a popular WordPress plugin vendor. The attack has forced the WordPress.org plugins team to temporarily disable downloads for affected products, leaving site owners scrambling to assess their exposure. This isn't your typical supply chain breach. According to Wordfence researcher Paolo Tresso, the attack stands out because zero source code files were modified within the official WordPress.org repository. Instead, the attackers found a cleverer way in—by poisoning JSON files that the plugins rely on for configuration and updates. ### What Actually Happened? Here's the short version: BdThemes plugins, which are used by thousands of WordPress sites, depend on JSON files to fetch data and manage settings. The attackers tampered with those files, injecting malicious payloads that could create rogue administrator accounts on any site running the affected plugins. Once an attacker gains admin access, the game is pretty much over. They can install backdoors, steal customer data, deface your site, or use it to launch further attacks. For anyone running a business online, that's a nightmare scenario. The clever part is that the attack flew under the radar for a while because the core plugin code looked clean. The bad stuff was hidden in the data files, not the code itself. That's a sneaky approach that caught many security scanners off guard. ### Why This Matters for Your Site If you're using any BdThemes plugins, this is a wake-up call. Supply chain attacks are becoming more common, and they're harder to detect because they exploit the trust we place in third-party developers. You might be doing everything right—strong passwords, two-factor authentication, regular updates—and still get hit through a plugin you didn't write. The WordPress.org team acted quickly to pull the affected plugins, but that doesn't help sites that already downloaded them. If you're affected, you need to check your user accounts for any unfamiliar admins right away. ### How to Protect Yourself Here are some practical steps to reduce your risk: - **Audit your admin accounts** – Log into your WordPress dashboard and review all users with administrator privileges. Remove anything you don't recognize. - **Update everything** – Once BdThemes releases a patched version, update immediately. Delaying updates is one of the biggest risk factors. - **Use a security plugin** – Tools like Wordfence or Sucuri can help detect suspicious activity and block malicious login attempts. - **Back up regularly** – Keep clean off-site backups so you can restore your site if something goes wrong. - **Limit plugin usage** – Every plugin you add is another potential entry point. Only install what you really need. ### The Bigger Picture This incident highlights a growing trend in cyberattacks. Instead of going after big targets directly, attackers are compromising smaller vendors and using them as a stepping stone. It's like breaking into a warehouse by stealing the delivery truck keys first. For WordPress users, the takeaway is clear: you can't just trust that a plugin is safe because it's on the official repository. The ecosystem is only as strong as its weakest link, and attacks like this remind us to stay vigilant. If you're running a site with BdThemes plugins, don't panic, but do act. Check your users, watch for suspicious activity, and keep an eye on the official announcements for when a fix is available. A few minutes of checking now could save you from a major headache later.