42
42
42
42
42
42
WordPress Plugins Compromised Without a Single File Change
Attackers poisoned bdThemes' JSON API feed to backdoor WordPress sites by serving malicious remote code without modifying plugin files.
Infosecurity Magazine reports a supply chain attack in which attackers poisoned a JSON feed used by bdThemes WordPress plugins. The compromised feed delivered malicious code that backdoored sites without changing any plugin files, evading file-integrity based detection. WordPress sites running the vendor's plugins were affected.
60
42
42
42
42
42
42
42
42
42
57
42
42
42
42
42
42
42
42
42
42
42
47
42
42
42
47
42
42
47
42
42
42
47