BdThemes supply chain attack poisoned JSON API exploiting XSS vulnerability to create rogue WordPress admin accounts and install webshells.
BdThemes supply chain attack poisons JSON feed to create rogue WordPress admins and deploy web shells without code changes.
BdThemes' compromised JSON feed exploits XSS in seven WordPress plugins, creating rogue admins and installing a PHP web shell without plugin updates.
Wordfence was notified of the compromise on August 7 and published its analysis the following day. It affects BdThemes, an Elementor add-on vendor whose plugins are distributed through the official ...
A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create ...
WordPress.com has just announced a brand new REST API, which gives developers access to tons of new content, including posts and comments, as well as the ability to Follow, Like, or Reblog content for ...
The recently patched REST API Endpoint vulnerability in WordPress could be leveraged to pull off stored cross-site scripting attacks. The recently patched WordPress REST API Endpoint vulnerability is ...
The WordPress team has addressed a security flaw in the API servers responsible for the CMS' update mechanism, which if exploited, would have allowed an attacker to deploy backdoors and malware to 27% ...
WordPress 6.9, scheduled for release on December 2, 2025, is shipping with a new Abilities API that introduces a new system designed to make advanced AI-driven functionality possible for themes and ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results