#bdthemes
A supply chain attack has hit all BdThemes WordPress plugins

Origin of the attack is an API that pulls promo banners in the plugin's WP backend via a cloud bucket

www.wordfence.com/blog/2026/08...
PSA: Supply Chain Compromise in BdThemes Ecosystem via Poisoned API Response
The Wordfence Threat Intelligence Team was notified on August 7th, 2026 of a supply chain compromise affecting BdThemes, a WordPress plugin vendor whose plugins are available in the official WordPress...
www.wordfence.com
August 8, 2026 at 11:17 PM
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts.
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts.
www.bleepingcomputer.com
August 10, 2026 at 9:12 PM
-Pwnie Awards 2026 winners
-Metabase zero-day used in data theft attacks
-Russian hackers disrupted a second power plant in Poland last year
-Two US law firms pay mega ransoms
-New WordPress RCE
-BdThemes supply chain attack

N: news.risky.biz/risky-bullet...
P: risky.biz/RBNEWS598/
August 10, 2026 at 7:52 AM
🚨 EUVD-2026-85460
📊 8.5/10
🏢 bdthemes

📝 Contributor SQL Injection in Live Copy Paste for Elementor <= 1.5.10 versions.

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85460

#cybersecurity #infosec #cve #euvd
September 23, 2026 at 8:04 PM
BdThemes plugins supply-chain hack creates rogue WordPress admins
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts. [...]
www.bleepingcomputer.com
August 10, 2026 at 9:23 PM
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Ravie LakshmananAug 11, 2026Supply Chain Attack / Vulnerability Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS)…
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Ravie LakshmananAug 11, 2026Supply Chain Attack / Vulnerability Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform’s plugins...
news-area.com
August 17, 2026 at 11:57 AM
BdThemes製WordPressプラグインで、供給網攻撃により不正な管理者アカウントが作成される脆弱性が発見されました。
BdThemes plugins supply-chain hack creates rogue WordPress admins
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create r...
www.bleepingcomputer.com
August 10, 2026 at 9:51 PM
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins

Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable …
#hackernews #news
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
thehackernews.com
August 12, 2026 at 1:06 AM
--AI-found Zoom flaws enabled silent device takeovers,
--DEF CON flight hit by hacker WiFi scare,
--LexisNexis takes services offline after suspicious activity,
--NATO, AI startup join ENISA’s CVE program,
--BdThemes supply-chain attack creates rogue WordPress admins, 3/6
August 11, 2026 at 2:19 PM
CVE-2026-78657 - sigmaforms pro – ai generated forms
All versions of the SigmaForms Pro – AI Generated Forms plugin for WordPress up through 1.4.11 let anyone send a specially crafted request that makes the site…

Too many irrelevant or confusing CVEs? Use stackflag.com

#bdthemes #CVE #infosec
CVE-2026-78657: SigmaForms Pro plugin can let attackers delete any file
All versions of the SigmaForms Pro – AI Generated Forms plugin for WordPress up through 1.4.11 let anyone send a specially crafted request that makes the.
stackflag.com
September 2, 2026 at 2:40 PM
CVE-2026-14494 - sigmaforms pro – ai generated forms
The Sigma Forms Pro add‑on for WordPress lets anyone on the internet send a file through its form fields, and the file can be placed on your server and executed…

Too many irrelevant or confusing CVEs? Use stackflag.com

#bdthemes #CVE #infosec
CVE-2026-14494: Sigma Forms Pro lets anyone upload files and run code
The Sigma Forms Pro add‑on for WordPress lets anyone on the internet send a file through its form fields, and the file can be placed on your server and.
stackflag.com
August 29, 2026 at 9:40 PM
WordPress site owners: take a quick security check.

Recent plugin vulnerabilities are a good reminder to keep plugins updated and review your site for anything unusual.

www.panstag.com/2026/08/word...

#WordPress #WordPressSecurity #CyberSecurity
Forminator and BdThemes Hacks: Is Your WordPress Site Affected? - Panstag
Two major WordPress plugin vulnerabilities hit in August 2026. Check if your site is affected and learn what to do next.
www.panstag.com
August 25, 2026 at 12:29 AM
A supply chain attack targeted BdThemes WordPress plugins by poisoning a remote JSON feed delivered through the admin dashboard.

Source: TechJuice
Hackers Make Fake Admin Accounts on Millions of WordPress Sites
BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
www.techjuice.pk
August 18, 2026 at 9:34 AM
🌐 A supply chain attack affecting BdThemes WordPress plugins highlights the security risks posed by website plugins.

✉️ Weekly cyber threat alerts and safety tips at www.cedtechnology.co.uk

#CyberSecurity #WordPress
August 14, 2026 at 3:29 PM