Kryptovalutaticker:
sysadmin från Cyber Security News

New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

Abinaya
6 hours ago
5 Visningar
0 Kommentarer
New WordPress Supply Chain Attack Compromises Themes via Poisoned API Response

A supply chain attack targeting BdThemes WordPress plugins has exposed site administrators to account takeover, webshell deployment, and persistent backdoors. Wordfence Threat Intelligence was notified of the incident on August 7, 2026, after discovering that attackers had poisoned a remote promotional API feed used by several popular BdThemes plugins. The affected plugins include Element Pack Addons for Elementor, Prime Slider Addons for Elementor, Pixel Gallery Addons for Elementor, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste, and Smart Admin Assistant. The WordPress Plugins team temporarily closed the plugins in the official directory while its investigation continues. The attack is notable because attackers did not...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!