Por Security Talent en Martes, 11 Agosto 2026
Categoría: Cybersecurity News, Threats & Industry Updates

El ataque a la cadena de suministro de BdThemes corrompe archivos JSON para crear administradores de WordPress no autorizados

Regional security update

Assess promptly

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

At a glance

  • Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
  • SecurityTalent reviewed the linked official source and preserved its attribution.

Why this matters

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

Teams should validate whether the development affects their technology, services, obligations or risk decisions.

Who should act

  • Security operations and incident response teams
  • Technology and service owners
  • Risk, compliance and security leaders

SecurityTalent action checklist

  1. Open the official source and confirm scope, affected systems and timing.
  2. Assign an accountable owner and assess exposure using current inventory.
  3. Apply the official guidance or document the risk decision and verification evidence.

Source and attribution

Primary source: BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Publisher
The Hacker News
Author / authority
The Hacker News
Published
August 11, 2026
SecurityTalent review
July 18, 2026

This is an original SecurityTalent summary and analysis based on the linked primary source. It is not a republication. The source controls if facts, versions or deadlines change after our review.

Publicaciones relacionadas

Dejar comentarios