ZeroHour
Infosecurity Magazinepublished ()ingested

WordPress Plugins Compromised Without a Single File Change

highMalware exploited in the wildimportance 60
AI summary · glm-5.3

Attackers poisoned bdThemes' JSON API feed to backdoor WordPress sites by serving malicious remote code without modifying plugin files.

Infosecurity Magazine reports a supply chain attack in which attackers poisoned a JSON feed used by bdThemes WordPress plugins. The compromised feed delivered malicious code that backdoored sites without changing any plugin files, evading file-integrity based detection. WordPress sites running the vendor's plugins were affected.

  • Supply chain attack via poisoned JSON API feed from bdThemes
  • Backdoor deployed with zero plugin file changes on victim sites
  • File-integrity monitoring would not detect the compromise
  • WordPress sites using bdThemes plugins are affected
Full article

Poisoned JSON feed let attackers backdoor WordPress sites without changing any plugin files

This source does not provide full text. Read it at infosecurity-magazine.com.