Login
← All news

BdThemes plugins supply-chain hack creates rogue WordPress admins

BleepingComputer by Bill Toulas WordPress Security
illustration

A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts.

Read the full story on BleepingComputer https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-creates-rogue-wordpress-admins/
Most WordPress sites are compromised through something ordinary: an unpatched plugin, an abandoned theme, an account without two-factor. If you would rather updates and backups simply happened, CrockyHost hosting does them for you.