Cybersecurity researchers have issued a warning about a supply chain compromise affecting BdThemes, a WordPress plugin vendor. As a result, the WordPress plugins team has temporarily disabled downloads of BdThemes' plugins.
The compromise is notable for its unconventional approach. According to Paolo Tresso, a researcher at Wordfence, the attack did not involve modifying any source code files within the official WordPress.org repository.
Instead, the attackers targeted the supply chain by poisoning JSON data, which ultimately led to the creation of rogue WordPress administrators. This tactic allowed the attackers to gain unauthorized access to WordPress sites using the compromised plugins.
The temporary disabling of BdThemes' plugins is a precautionary measure to prevent further exploitation of the vulnerability. WordPress users who have installed plugins from BdThemes are advised to exercise caution and monitor their sites for any suspicious activity.
The incident highlights the importance of vigilance in maintaining the security of content management systems and plugins. As the investigation into the supply chain compromise continues, WordPress users and developers are reminded to stay informed about potential security risks and take proactive steps to protect their sites.
Further details about the compromise and the affected plugins have not been disclosed. However, the WordPress community is awaiting updates on the incident and guidance on how to mitigate its impact.
<small>Source: The Hacker News — read the original story there.</small>