cybersecuritysupply-chain attackwordpresssmall businessescanada

BdThemes plugins supply-chain hack creates rogue WordPress admins

August 10, 2026

Back to all posts

Source: BleepingComputer

A supply-chain attack on BdThemes, a popular WordPress theme provider, has resulted in the unauthorized insertion of malicious code within several of their plugins. The malware, dubbed 'GovHighRoller', is designed to grant attackers administrative access to compromised websites. This incident poses a significant threat to Canadian businesses as many SMBs rely on WordPress and third-party plugins for their website management. Cybercriminals can use this backdoor to inject malware, conduct data theft, or deface websites, potentially leading to financial losses, damaged reputation, and legal consequences. To mitigate this risk, it is crucial for Canadian businesses to keep their WordPress installations, themes, and plugins updated regularly and consider implementing multi-factor authentication (MFA) on administrator accounts.
cybersecuritysupply-chain attackwordpresssmall businessescanada

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment