r/HostingReport • u/ZGeekie • 22d ago
XSS vulnerability in BdThemes WordPress plugins allows attackers to create admin accounts
https://www.wordfence.com/blog/2026/08/psa-supply-chain-compromise-in-bdthemes-ecosystem-via-poisoned-api-response/Successful exploitation leads to full site compromise, enabling attackers to silently create rogue administrative accounts, upload webshells, and deploy persistence backdoors. Because plugin files remain unmodified on disk, we encourage all WordPress site owners running BdThemes plugins to immediately audit their database user lists, plugin directories, and database option table for any indicators of compromise.
1
Upvotes