What's Happening?
A supply chain attack has targeted BdThemes, a vendor of WordPress plugins, leading to the temporary disabling of several plugins. The attack involved the poisoning of a static remote JSON data stream used by an administrative promotional banner component,
without modifying any source code files in the WordPress.org repository. Affected plugins include Element Pack Addons for Elementor and Live Copy Paste for Elementor, among others. The attack exploited a cross-site scripting (XSS) vulnerability in the JSON response parsing code, allowing attackers to inject scripts that create rogue administrator accounts and upload web shell plugins.
Why It's Important?
This attack highlights the vulnerabilities in software supply chains, particularly in widely used platforms like WordPress. The ability to create rogue administrator accounts poses significant security risks, potentially allowing unauthorized access and control over affected websites. This incident underscores the need for robust security measures and monitoring to protect against such attacks. The impact on businesses and individuals using these plugins could be substantial, as compromised websites may face data breaches, service disruptions, and reputational damage.
What's Next?
WordPress and BdThemes are conducting a full review of the affected plugins to address the vulnerabilities and prevent future attacks. Users are advised to monitor updates from WordPress and BdThemes and to implement additional security measures to protect their websites. The incident may prompt broader discussions and actions within the tech community to enhance supply chain security and develop more resilient systems against such attacks.











