Skip to main content

Tag: json poisoning

1 article

WordPress admin dashboard on a laptop screen with a cityscape background and office items nearby.

BdThemes Plugins Targeted in Supply Chain Attack

A sneaky supply chain attack used a BdThemes plugin component to secretly inject malicious code into WordPress dashboards, creating backdoors and deploying stealthy modules without ever touching the plugin files on disk. This clever compromise exploited a vulnerability in the Biggopti library to poison JSON data and trigger an XSS flaw.

Analyst 207