Wordfence
Coverage of Wordfence in the Nexus archive.
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
A supply chain compromise impacted WordPress plugin vendor BdThemes, leading the CMS platform's plugins team to temporarily disable their downloads. Cybersecurity researchers issued warnings regarding this issue. However, they noted that zero source code files were modified within the official WordPress.org repository.
- What happens if you visit a WordPress site hacked through wp2shell?
WordPress patched a critical core vulnerability chain called wp2shell, which allows attackers to gain full control of sites without authentication, leading to risks like credential theft, malware delivery, and malicious redirects for visitors. Attackers have already begun exploiting the flaw, injecting harmful content and compromising user trust.
- ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after threat actors injected backdoor code into Pro plugin releases through official licensed update channels. Wordfence analyzed the incident, confirming the vendor's build and distribution pipeline was compromised.