A New Type of Supply Chain Attack Threatens WordPress Sites: Meet BdThemes
In a disturbing example of how malicious actors can compromise even the most seemingly secure systems, a recent supply chain attack has left hundreds of WordPress sites vulnerable to takeover by rogue administrators. The culprit behind this breach is a theme supplier called BdThemes, which has been quietly injecting poisoned JSON code into its products. This insidious tactic allows hackers to gain elevated privileges on affected sites, essentially granting them control over the entire platform.
The BdThemes supply chain attack works by exploiting the trust that WordPress site owners place in their theme providers. By injecting malicious code into the JSON files used by these themes, attackers can manipulate the permissions and access levels for various system users. In this case, the poisoned code creates new administrative accounts on affected sites, allowing hackers to assume control and potentially take over the entire platform. This type of attack is particularly concerning because it doesn’t require a user to click on any malicious links or download any malware; simply installing the compromised theme is enough to trigger the breach.
The impact of this attack has been significant, with hundreds of WordPress sites affected worldwide. The BdThemes compromise has also highlighted the importance of ensuring that third-party plugins and themes are properly vetted for security vulnerabilities before being installed on a site. While BdThemes itself appears to have taken steps to address the issue, many users remain at risk unless they take immediate action to update their themes or remove the affected ones altogether.
The BdThemes supply chain attack is a stark reminder that even the most seemingly secure systems can be compromised through subtle and sophisticated tactics. This type of attack underscores the importance of staying vigilant in the face of evolving threats and regularly reviewing and updating one’s security posture. As with any security breach, it’s essential to take prompt action to mitigate the damage and prevent further exploitation.
For WordPress site owners, this incident serves as a stark reminder to scrutinize their theme suppliers more closely and ensure that they are using reputable providers who have robust security measures in place. By taking proactive steps to safeguard your site against similar supply chain attacks, you can help protect yourself from the devastating consequences of such breaches.
Source: The Hacker News — 2026-08-11