Cybersecurity researchers report that a supply-chain compromise targeting BdThemes affects WordPress sites using its premium plugins. The attacker compromises BdThemes’ upstream infrastructure and alters a remote JSON feed that the plugins access, resulting in the creation of unauthorized (“rogue”) WordPress administrator accounts.

According to multiple reports, the manipulation occurs in content delivered to administrators’ browsers rather than through changes to WordPress.org plugin source files. Researchers say the attack does not involve direct tampering with code hosted in the official WordPress.org repository, distinguishing it from some traditional supply-chain methods. Wordfence also notes that no official repository source files are modified.

Bleeping Computer describes how the altered JSON feed enables the rogue admin accounts in the WordPress environment, while the Hacker News report highlights that WordPress plugins team actions include temporarily disabling plugin downloads as a precaution. The outlets broadly agree on the upstream compromise, the use of a modified remote JSON feed, and the resulting impact on WordPress administrator access.