New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the incident on August 7, 2026, after discovering that attackers had poisoned a remote promotional API feed used by several popular BdThemes plugins. The affected plugins include Element Pack […]

This article has been indexed from Cyber Security News

Read the original article: