A supply-chain attack on BdThemes, a developer of premium WordPress design tools, has resulted in unauthorized administrator accounts being created on customer sites. The breach targeted the vendor’s upstream infrastructure, specifically a remote JSON feed delivered to administrators’ browsers during plugin updates or configuration checks.
What happened
Attackers modified the JSON feed to include instructions that generated rogue WordPress admin accounts on sites using BdThemes plugins. The method leveraged the feed’s legitimate delivery mechanism, bypassing traditional file-based malware detection. No details were provided about the number of affected sites, the duration of the compromise, or how the attackers initially gained access to BdThemes’ systems.
BdThemes has not publicly disclosed whether the compromised feed has been secured or if patches have been issued to remove the malicious payload. The vendor also did not confirm whether all affected customers have been notified.
What we don’t know yet
The scope of the breach remains unclear. Sources did not specify how many sites were impacted, whether the attack was targeted or opportunistic, or if additional malicious payloads were distributed beyond the rogue admin accounts. The timeline of the compromise—including when the attackers first gained access and when the tampered feed was active—was also not disclosed. Without further details, it is difficult to assess the full risk to users or the effectiveness of remediation efforts.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 10 Aug 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — Failed no verdict returned
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No recent or in-pipeline article covers this BdThemes supply-chain WordPress compromise.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers this specific BdThemes supply-chain WordPress hack.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=413 slug=bdthemes-supply-chain-hack-creates-rogue-wordpress-admins quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: Source does not confirm whether the compromised feed has been secured, patches issued, or all affected customers notified. These claims are unsupported and should be removed or qualified as unknown.
- Style compliance: The phrase 'No details were provided about...' is repeated in both 'What happened' and 'What we don’t know yet' sections, which could be consolidated for conciseness.
- Audience relevance and notability: While the story is relevant to WordPress professionals, the lack of concrete details (e.g., number of affected sites, timeline) limits its actionable impact. However, the supply-chain angle remains notable for the hosting and security audience.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Rejected library image #28: The candidate (index 0) depicts riot police with shields, which is unrelated to WordPress administration, supply-chain attacks, or security breaches. The alt text and query do not match the article topic, and there is no clear connection to the described incident or the primary company (BdThemes).
- Assigning hero image — Rejected library image #283: No candidate matches the article topic (supply-chain hack, WordPress admin compromise) with sufficient relevance. Candidate 0 is unrelated (post-quantum cryptography concept illustration) and does not depict supply-chain attacks, WordPress, or admin accounts.
- Assigning hero image — Unsplash unsplash_id=NYcUkFJuxg0 q=JSON configuration file code snippet picker=The candidate depicts a computer screen with a bunch of text, which aligns closely with the article's focus on a supply-
- Linking related stories — Linked 3 relations from 354 candidates
- Publishing — Published bdthemes-supply-chain-hack-creates-rogue-wordpress-admins
- Mastodon — Posted https://mstdn.social/@hostingpaper/117073902442975137




Discussion · coming soon
Be the first to join the thread when community discussion launches.