Decision RecordActivePublished without chair review
CRT-2026-022911 Aug 2026MORNING EDITIONDaily Roundtable
BdThemes WordPress plugin containment
For affected or potentially affected BdThemes WordPress products, disable the components until administrators can verify a clean source, snapshot sites, inspect administrator accounts, plugin installs, web roots, scheduled tasks, MU-plugins, and outbound connections, and rotate credentials where untrusted code may have run.
Current public guidance · the full record
What to do now
At a glanceThe edition's authoritative action board carries no action for this record's subjects — no What to do now guidance.
Why now
Under reviewAct now because the cited Roundtable material treats BdThemes as a live WordPress supply-chain blast-radius problem, not a normal plugin maintenance issue.
The final synthesis says researchers reported a poisoned promotional-banner JSON path creating rogue WordPress administrators, fake plugins, web shells, and persistence.
The supply-chain analyst discussion says WordPress plugin update and content channels are reaching production sites and recommends action that night: freeze BdThemes plugin and theme updates, snapshot sites, and inspect for administrator and plugin changes.
The evidence review supports containment and inspection while noting that exact affected versions and clean-release evidence are not present, so delay should not be used to wait for perfect package precision on sites already using affected or potentially affected BdThemes products.
Who is affected
Under reviewWordPress site owners and administrators using affected or potentially affected BdThemes products are the primary affected group; their exposure is untrusted code reaching production sites through a reported promotional-banner JSON distribution path.
Managed WordPress providers and agencies maintaining client sites with BdThemes products are affected because they may need to freeze vendor update paths, snapshot multiple sites, inspect administrator accounts and plugin state, and coordinate credential rotation.
Site users and site visitors are indirectly affected if a compromised WordPress site contains rogue administrator access, fake plugins, web shells, persistence, or outbound activity that changes site behavior or exposes data.
The packet does not identify exact BdThemes plugin names, theme names, affected versions, or clean versions.
What supports this
Under reviewThe final synthesis supports separate urgency for BdThemes WordPress products: it says researchers reported a poisoned promotional-banner JSON path that created rogue WordPress administrators, fake plugins, web shells, and persistence.
The supply-chain analyst discussion supports immediate containment: it describes BdThemes first as a live blast-radius problem and recommends freezing plugin and theme updates from that vendor, snapshotting affected sites, and reviewing recent WordPress administrator users and unexpected plugin changes.
The handoff component supports the supply-chain framing: it labels the BdThemes WordPress plugins issue as a software supply-chain compromise.
The handoff usage note supports the specific reported path and consequence: it pairs BdThemes with a poisoned promotional-banner JSON path, WordPress rogue administrators, and backdoor language.
The retrieval summary is weaker contextual support: it shows the query and current-handoff result for BdThemes poisoned promotional-banner JSON, but it is not itself an authoritative advisory.
How the Roundtable reached this
Under reviewThe Roundtable separated the BdThemes WordPress issue from routine plugin hygiene because the cited discussion described a reported promotional-banner JSON distribution path reaching production sites and creating rogue WordPress administrators, fake plugins, web shells, and persistence.
The supply-chain analyst argued for immediate containment: freeze BdThemes plugin and theme update paths, snapshot sites, and inspect for new administrator accounts and unexpected plugin changes.
The evidence review supported those operational steps but identified a concrete gap: the packet does not provide an authoritative affected-product list, version list, hashes, or clean-release evidence.
The boundary review resolved the wording risk by limiting the recommendation to affected or potentially affected BdThemes WordPress products and avoiding a claim that every BdThemes deployment is confirmed compromised. The arbiter accepted this as a new operational action with scoped public wording.
Positions are generated by AI specialist personas and chaired by Halil Öztürkci.
Panel composition
- Scout (AI panel role)Scout identified 8 candidate signals.
- Linker (AI panel role)Linker evaluated 8 relation judgments.
- Evidence Auditor (AI panel role)Evidence Auditor recorded 17 evidence signals; 9 gaps.
- Prediction Steward (AI panel role)Prediction Steward accepted 1 prediction and rejected 1 claim.
- Boundary Reviewer (AI panel role)Boundary Reviewer recorded 13 public/private findings.
- Arbiter (AI panel role)Arbiter produced 8 decision envelopes.
Key disagreement
Scout (AI panel role)
The discussion describes the issue as reported by researchers, and detailed package or site-level validation still needs audit. The response is scoped to organizations using affected BdThemes products or seeing related WordPress indicators.
Arbiter outcome
Arbiter outcome: new decision record. Supported operational action with no linked prior record. The evidence gap is limited to affected-product precision and can be handled with scoped public wording.
Candidates considered
Considered 8 candidates · opened 1 · 7 not opened (7 other)
Considered, not opened
Sign in to preview Considered-Not-Opened entries (moves to Pro at launch).
Sign in to preview practitioner entries.
What is uncertain
MissingThe exact BdThemes WordPress products and versions affected are uncertain.
The packet frames the issue as reported by researchers and supports containment, but it does not provide package-level validation, hashes, clean-release evidence, or a verified inventory of compromised sites.
It is also uncertain whether a specific WordPress site using BdThemes products actually executed untrusted code; that has to be determined by site inspection for administrator-account changes, plugin and MU-plugin changes, web-root changes, scheduled tasks, outbound connections, and other persistence indicators.
What evidence is missing
MissingThe packet does not include a concrete list of affected BdThemes WordPress plugins or themes, affected versions, fixed or clean versions, file hashes, package identifiers, site telemetry, or an authoritative public advisory.
It also does not include enough source detail to decide exactly which BdThemes components can be safely restored without site-level inspection.
That missing evidence is why the action is scoped to affected or potentially affected BdThemes WordPress products rather than all WordPress sites or all BdThemes software.
What would change this
Under reviewThe recommendation can narrow if authoritative evidence identifies the exact BdThemes WordPress plugins or themes, affected versions, clean versions, and hashes.
It can relax for a specific site only after administrators verify that the installed BdThemes source is clean and the site has no new administrator accounts, fake plugins, MU-plugin persistence, web shells, suspicious scheduled tasks, web-root changes, or unexplained outbound connections.
It should escalate if evidence shows confirmed execution of untrusted code, broader BdThemes distribution-path compromise, or persistence on inspected WordPress sites.
What to watch next
Under reviewWatch for an authoritative BdThemes advisory, affected plugin and theme names, affected versions, fixed or clean versions, and file hashes.
Watch your own WordPress estate for newly created administrator accounts, unexpected plugins, MU-plugin additions, web-root changes, scheduled tasks, web shells, and unusual outbound connections.
If a clean BdThemes release and affected-version list are published, use them to narrow containment and decide which components can be restored.
If site inspection finds persistence or untrusted code execution, keep the component disabled, preserve the snapshot, complete cleanup, and rotate credentials before restoration.
Evidence basis
Cited material · 1
CyberBrief handoff usage tool_call with attributed attribution. BdThemes - WordPress plugins - supply chain compromise BdThemes poisoned promotional-banner JSON WordPress rogue admin backdoor
Panel context · 5
BdThemes poisoned promotional-banner JSON WordPress rogue admin backdoor Found 5 results for "BdThemes poisoned promotional-banner JSON WordPress rogue admin backdoor" (hybrid search + 3 current handoff hit(s)). Retrieval order: current_han…
Summary: Today’s decision story is exposed trust infrastructure under active pressure: per the briefing, CISA KEV now includes Progress LoadMaster CVE-2026-8037, while SonicWall SMA1000, Check Point VPN, Fortinet, and N-able N-central activ…
Public value history
- 11 Aug 2026Initial public guidanceCurrent guidance
Created the first public value version for this Decision Record.
Source RoundtableMorning roundtableConvened 11 Aug 2026Methodology
How the panel reaches a Public Decision Record.