Wordfence was notified of the compromise on August 7 and published its analysis the following day. It affects BdThemes, an Elementor add-on vendor whose plugins are distributed through the official ...
BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
WordPress 6.9, scheduled for release on December 2, 2025, is shipping with a new Abilities API that introduces a new system designed to make advanced AI-driven functionality possible for themes and ...
By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the finders a hotfix.
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create ...
BdThemes supply chain attack poisons JSON feed to create rogue WordPress admins and deploy web shells without code changes.
New York, NY, July 23rd, 2026, FinanceWireFree, no-code plugin lets any WordPress publisher set machine-readable terms for ...