Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ShapedPlugin WordPress Plugins Hit by Supply Chain Attack

ShapedPlugin WordPress Plugins Hit by Supply Chain Attack

Posted on June 22, 2026 By CWS

In a recent cybersecurity incident, several WordPress plugins from ShapedPlugin were compromised through a supply chain attack. This breach allowed unknown attackers to manipulate official distribution channels, embedding malicious backdoor code into Pro plugin updates.

Details of the Compromise

Wordfence, a WordPress security firm, revealed that the attackers infiltrated the vendor’s build and distribution systems. They injected backdoor code into the Pro versions of plugins, which were distributed through official licensed update channels. The affected plugins include Product Slider Pro for WooCommerce (versions before 3.5.4), Real Testimonials Pro (version 3.2.5), and Smart Post Show Pro (versions before 4.0.2).

Notably, this breach only impacts the Pro versions distributed via ShapedPlugin’s Easy Digital Downloads (EDD) system at account.shapedplugin[.]com, leaving free versions on WordPress.org untouched.

Severity and Impact

The supply chain breach concerning Product Slider Pro for WooCommerce has been designated CVE-2026-49777, with a critical CVSS score of 10.0. The overall incident bears the CVE identifier CVE-2026-10735, scoring 9.8. The compromised plugins utilize a loader that activates with every admin page load, retrieving a payload from a remote server to install a fake plugin.

Once deployed, the malware communicates the compromised domain back to the server, then removes itself to hinder response measures. It also hides from the WordPress admin plugin list, capturing credentials and 2FA codes in plaintext.

Technical Exploitation and Response

The attack includes multiple persistence strategies, allowing arbitrary file writes via a REST endpoint with a specific authentication token, and deploying a web shell with command execution capabilities. A PHP script named “install-persistent.php” is used, extracting data such as wp-config.php contents, admin account details, mail plugin credentials, and recent WooCommerce order data.

This file is subsequently deleted to obscure the attack. The breach likely resulted from a compromise in the build pipeline rather than the direct tampering of packages.

ShapedPlugin acknowledged the incident and is reassessing its release processes to fortify product integrity. Updated versions of the affected plugins will undergo thorough security evaluations before release.

Recommendations and Future Measures

Site owners using the compromised versions are advised to reset all passwords, revoke and regenerate 2FA secrets, scrutinize admin accounts for unauthorized changes, and examine mail plugin configurations for altered SMTP credentials.

ShapedPlugin’s swift response and commitment to security reviews signal a proactive stance in safeguarding its user base against future threats.

The Hacker News Tags:Backdoor, CVE-2026-10735, CVE-2026-49777, Cybersecurity, Malware, security breach, ShapedPlugin, supply chain attack, Wordfence, WordPress plugins

Post navigation

Previous Post: Microsoft Entra CAPs Bypass via Nested App Authentication
Next Post: LLM API Credentials Leak in AI iOS Apps: A Growing Concern

Related Posts

Critical MOVEit Automation Flaw Patches Released by Progress Critical MOVEit Automation Flaw Patches Released by Progress The Hacker News
Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL Server Microsoft Patches 130 Vulnerabilities, Including Critical Flaws in SPNEGO and SQL Server The Hacker News
Microsoft Addresses High-Severity Windows Admin Center Flaw Microsoft Addresses High-Severity Windows Admin Center Flaw The Hacker News
How Threat Hunting Builds Readiness How Threat Hunting Builds Readiness The Hacker News
AI Model Unveils Software Flaws, Raises Fixing Concerns AI Model Unveils Software Flaws, Raises Fixing Concerns The Hacker News
Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple Resolves Security Flaw in Beats Studio Buds
  • Weekly Cyber Threat Summary: Major Incidents Unveiled
  • LLM API Credentials Leak in AI iOS Apps: A Growing Concern
  • ShapedPlugin WordPress Plugins Hit by Supply Chain Attack
  • Microsoft Entra CAPs Bypass via Nested App Authentication

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple Resolves Security Flaw in Beats Studio Buds
  • Weekly Cyber Threat Summary: Major Incidents Unveiled
  • LLM API Credentials Leak in AI iOS Apps: A Growing Concern
  • ShapedPlugin WordPress Plugins Hit by Supply Chain Attack
  • Microsoft Entra CAPs Bypass via Nested App Authentication

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark