Decision RecordActivePublished without chair review

BdThemes WordPress plugin containment

WordPress supply-chain containment

Reader challenge

Challenge this conclusion

Contest a specific conclusion. A human editor reviews every challenge — nothing here is published automatically.

Security check loading…
Confidence
High
Section support
High confidence · 0/8 backed · 2 gaps · panel
Severity
High
Assessed severity
Panel
AI roles · 1 disagreement
Freshness · v2
Last updated 8 days ago
Last revised 2026-08-11
Active6 evidence references · Published 11 Aug 2026 · Daily RoundtableServer-rendered freshness may trail the latest update by the page cache window.
Current position

For affected or potentially affected BdThemes WordPress products, disable the components until administrators can verify a clean source, snapshot sites, inspect administrator accounts, plugin installs, web roots, scheduled tasks, MU-plugins, and outbound connections, and rotate credentials where untrusted code may have run.

Public guidance

Current public guidance · the full record

Current public value version · v2
01

What to do now

At a glance

The edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.

02

Why now

Under review

Act now because the cited Roundtable material treats BdThemes as a live WordPress supply-chain blast-radius problem, not a normal plugin maintenance issue.

The final synthesis says researchers reported a poisoned promotional-banner JSON path creating rogue WordPress administrators, fake plugins, web shells, and persistence.

The supply-chain analyst discussion says WordPress plugin update and content channels are reaching production sites and recommends action that night: freeze BdThemes plugin and theme updates, snapshot sites, and inspect for administrator and plugin changes.

The evidence review supports containment and inspection while noting that exact affected versions and clean-release evidence are not present, so delay should not be used to wait for perfect package precision on sites already using affected or potentially affected BdThemes products.

03

Who is affected

Under review

WordPress site owners and administrators using affected or potentially affected BdThemes products are the primary affected group; their exposure is untrusted code reaching production sites through a reported promotional-banner JSON distribution path.

Managed WordPress providers and agencies maintaining client sites with BdThemes products are affected because they may need to freeze vendor update paths, snapshot multiple sites, inspect administrator accounts and plugin state, and coordinate credential rotation.

Site users and site visitors are indirectly affected if a compromised WordPress site contains rogue administrator access, fake plugins, web shells, persistence, or outbound activity that changes site behavior or exposes data.

The packet does not identify exact BdThemes plugin names, theme names, affected versions, or clean versions.

04

What supports this

Under review

The final synthesis supports separate urgency for BdThemes WordPress products: it says researchers reported a poisoned promotional-banner JSON path that created rogue WordPress administrators, fake plugins, web shells, and persistence.

The supply-chain analyst discussion supports immediate containment: it describes BdThemes first as a live blast-radius problem and recommends freezing plugin and theme updates from that vendor, snapshotting affected sites, and reviewing recent WordPress administrator users and unexpected plugin changes.

The handoff component supports the supply-chain framing: it labels the BdThemes WordPress plugins issue as a software supply-chain compromise.

The handoff usage note supports the specific reported path and consequence: it pairs BdThemes with a poisoned promotional-banner JSON path, WordPress rogue administrators, and backdoor language.

The retrieval summary is weaker contextual support: it shows the query and current-handoff result for BdThemes poisoned promotional-banner JSON, but it is not itself an authoritative advisory.

05

How the Roundtable reached this

Under review

The Roundtable separated the BdThemes WordPress issue from routine plugin hygiene because the cited discussion described a reported promotional-banner JSON distribution path reaching production sites and creating rogue WordPress administrators, fake plugins, web shells, and persistence.

The supply-chain analyst argued for immediate containment: freeze BdThemes plugin and theme update paths, snapshot sites, and inspect for new administrator accounts and unexpected plugin changes.

The evidence review supported those operational steps but identified a concrete gap: the packet does not provide an authoritative affected-product list, version list, hashes, or clean-release evidence.

The boundary review resolved the wording risk by limiting the recommendation to affected or potentially affected BdThemes WordPress products and avoiding a claim that every BdThemes deployment is confirmed compromised. The arbiter accepted this as a new operational action with scoped public wording.

Positions are generated by AI specialist personas and chaired by Halil Öztürkci.

Panel composition

  • Scout (AI panel role)Scout identified 8 candidate signals.
  • Linker (AI panel role)Linker evaluated 8 relation judgments.
  • Evidence Auditor (AI panel role)Evidence Auditor recorded 17 evidence signals; 9 gaps.
  • Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
  • Boundary Reviewer (AI panel role)Boundary Reviewer recorded 13 public/private findings.
  • Arbiter (AI panel role)Arbiter produced 8 decision envelopes.

Key disagreement

Scout (AI panel role)

The discussion describes the issue as reported by researchers, and detailed package or site-level validation still needs audit. The response is scoped to organizations using affected BdThemes products or seeing related WordPress indicators.

Arbiter outcome

Arbiter outcome: new decision record. Supported operational action with no linked prior record. The evidence gap is limited to affected-product precision and can be handled with scoped public wording.

Candidates considered

Considered 8 candidates · opened 1 · 7 not opened (7 other)

Considered, not opened

Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).

Sign in to preview practitioner entries.

06

What is uncertain

Missing

The exact BdThemes WordPress products and versions affected are uncertain.

The packet frames the issue as reported by researchers and supports containment, but it does not provide package-level validation, hashes, clean-release evidence, or a verified inventory of compromised sites.

It is also uncertain whether a specific WordPress site using BdThemes products actually executed untrusted code; that has to be determined by site inspection for administrator-account changes, plugin and MU-plugin changes, web-root changes, scheduled tasks, outbound connections, and other persistence indicators.

07

What evidence is missing

Missing

The packet does not include a concrete list of affected BdThemes WordPress plugins or themes, affected versions, fixed or clean versions, file hashes, package identifiers, site telemetry, or an authoritative public advisory.

It also does not include enough source detail to decide exactly which BdThemes components can be safely restored without site-level inspection.

That missing evidence is why the action is scoped to affected or potentially affected BdThemes WordPress products rather than all WordPress sites or all BdThemes software.

08

What would change this

Under review

The recommendation can narrow if authoritative evidence identifies the exact BdThemes WordPress plugins or themes, affected versions, clean versions, and hashes.

It can relax for a specific site only after administrators verify that the installed BdThemes source is clean and the site has no new administrator accounts, fake plugins, MU-plugin persistence, web shells, suspicious scheduled tasks, web-root changes, or unexplained outbound connections.

It should escalate if evidence shows confirmed execution of untrusted code, broader BdThemes distribution-path compromise, or persistence on inspected WordPress sites.

09

What to watch next

Under review

Watch for an authoritative BdThemes advisory, affected plugin and theme names, affected versions, fixed or clean versions, and file hashes.

Watch your own WordPress estate for newly created administrator accounts, unexpected plugins, MU-plugin additions, web-root changes, scheduled tasks, web shells, and unusual outbound connections.

If a clean BdThemes release and affected-version list are published, use them to narrow containment and decide which components can be restored.

If site inspection finds persistence or untrusted code execution, keep the component disabled, preserve the snapshot, complete cleanup, and rotate credentials before restoration.

Sources & context

Evidence basis

6 references

Cited material · 1

Context
CyberBrief handoff usage tool_call with attributed attribution. BdThemes - WordPress plugins - supply chain compromise B…
gbhackers.com

CyberBrief handoff usage tool_call with attributed attribution. BdThemes - WordPress plugins - supply chain compromise BdThemes poisoned promotional-banner JSON WordPress rogue admin backdoor

Observed 11 Aug 2026
checked Aug 16, 2026

Panel context · 5

Context
BdThemes poisoned promotional-banner JSON WordPress rogue admin backdoor Found 5 results for "BdThemes poisoned promotio…

BdThemes poisoned promotional-banner JSON WordPress rogue admin backdoor Found 5 results for "BdThemes poisoned promotional-banner JSON WordPress rogue admin backdoor" (hybrid search + 3 current handoff hit(s)). Retrieval order: current_han…

Observed 11 Aug 2026
Context
Interaction
Observed 11 Aug 2026
Context
Summary: Today’s decision story is exposed trust infrastructure under active pressure: per the briefing, CISA KEV now in…

Summary: Today’s decision story is exposed trust infrastructure under active pressure: per the briefing, CISA KEV now includes Progress LoadMaster CVE-2026-8037, while SonicWall SMA1000, Check Point VPN, Fortinet, and N-able N-central activ…

Observed 11 Aug 2026
Context
Memory chunk
Observed 11 Aug 2026
Revision trail

Public value history

1 event on record
2 value versions · 1 update · 0 predictions
  1. 11 Aug 2026Initial public guidanceCurrent guidance

    Created the first public value version for this Decision Record.

Unified Search

Search the public record.