🔐
Security 📅 2026-08-11 · 04:37 AM IST ⏱ 3 min read

WordPress Plugin Maker Breached, Attackers Secretly Create Admin Accounts

Hackers infiltrated BdThemes infrastructure and planted backdoor access into WordPress sites using compromised software updates.

The Attack: How It Happened

Cybercriminals have successfully broken into the systems of BdThemes, a company that creates design tools for WordPress websites. Once inside, the attackers did something particularly sneaky: they modified the automatic update files that get sent to website administrators. Think of it like poisoning a delivery truck—the legitimate product arrives, but it contains hidden cargo that serves the attacker's purposes.

The hackers changed a configuration file (stored in JSON format) that administrators' browsers download regularly. This file normally contains harmless settings, but the criminals inserted malicious instructions that automatically created new administrator accounts on thousands of websites. These fake admin accounts gave the attackers complete control over the compromised sites, without the real owners knowing what happened.

Why This Attack Method Is So Dangerous

This technique exploits something that usually makes the internet safer: automatic updates. Millions of website owners trust their tools to update themselves. They assume that if an update goes through, it must be legitimate. An attacker who can intercept or modify these updates reaches an enormous number of targets at once.

The BdThemes situation is like someone breaking into a factory that makes locks and then putting faulty locks into the supply chain. All those faulty locks end up protecting homes and businesses, but they actually contain a hidden spare key for the criminal.

What This Means for Website Owners

If your website uses BdThemes plugins or tools, you could be affected. Unauthorized admin accounts sitting on your server could allow attackers to:

The scary part is you might not notice. An attacker with hidden admin access can be extremely quiet, watching and waiting rather than causing immediate damage.

What You Should Do Right Now

If you use BdThemes products:

For all website owners:

This attack reminds us that even trusted developers can be compromised. The solution isn't to stop updating—updates protect you—but to stay vigilant about monitoring what happens on your site.

The Bigger Picture

Supply chain attacks like this one have become increasingly common. Criminals now realize that breaking into one company's systems can give them access to thousands of downstream customers. This means software developers, plugin makers, and tool creators must treat security as a top priority, and website owners must maintain active oversight of their digital property.

Stay alert, stay updated, and don't assume that a legitimate-looking update is always safe without verification.

📎 This is original ITVedas reporting. This story was inspired by coverage from bleepingcomputer.com. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →