Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

WordPress Plugin Supply Chain Attack Could Let Hackers Create Fake Admin Accounts

A security issue has been found in a popular WordPress plugin where attackers can inject harmful code to create fake administrator accounts. This could let hackers take control of your website without your knowledge, which is a serious risk for small businesses using WordPress.

11 August 2026

1. What is being reported?

Hackers have exploited a supply chain attack targeting a WordPress plugin called BdThemes. They manipulate data sent to the plugin to secretly add rogue administrator accounts, giving them full control over affected websites.

2. What this means in plain English

If your website uses this plugin, attackers could gain access to your site, change content, steal information, or use your site for malicious activities. This can damage your reputation and disrupt your business operations.

3. Could this affect a small business?

Small businesses using WordPress with the BdThemes plugin installed are at risk. If you do not use WordPress or this specific plugin, you are unlikely to be affected.

4. What to do now

  • Check if your WordPress site uses the BdThemes plugin and remove or update it immediately.
  • Review your website’s administrator accounts for any unfamiliar users and remove them.
  • Ensure your WordPress installation and all plugins are kept up to date with the latest security patches.
  • Ask your IT provider to scan your website for signs of compromise and secure it against further attacks.

5. Ask your IT provider

Can you check if our WordPress site uses the BdThemes plugin and confirm it is secure from the recent supply chain attack that allows rogue admin accounts?

6. Bottom line

Act quickly to check and secure your WordPress site if you use the affected plugin to prevent hackers from taking control.

Information based on reputable security reporting and CISA KEV.

Back to Vulnerability Briefs