WordPress Plugin API Hit by Supply Chain Attack

Attackers have launched a supply chain attack targeting BdThemes WordPress plugins, injecting cross-site scripting (XSS) via a promotional banner feed. This method creates rogue admin accounts and installs backdoors without altering plugin source code, making detection difficult for traditional security scanners. The incident poses a significant risk to affected WordPress sites and their administrators.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai