ShapedPlugin update flow hacked to infect WordPress sites
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system. [...]
AI Analysis
Technical Summary
ShapedPlugin's build pipeline was compromised, allowing attackers to inject a malicious loader (LicenseLoader.php) into three paid WordPress plugins. When an administrator accessed the WordPress admin panel, the loader contacted a command-and-control server to download a backdoor disguised as a fake WooCommerce plugin. This backdoor was hidden from the plugin list and stole WordPress login credentials, 2FA secrets, database credentials, SMTP credentials, and recent WooCommerce order data. The attack was confirmed by Wordfence and tracked under CVE-2026-10735 (with a duplicate CVE-2026-49777). The vendor released fixed versions: Product Slider Pro 3.5.4, Real Testimonials Pro 3.2.6, and Smart Post Show Pro 4.0.2. The compromise appears limited to the vendor's release infrastructure, as WordPress.org hosted releases were clean.
Potential Impact
The supply chain compromise allowed attackers to distribute malware to paying customers via official plugin updates. The malware enabled credential theft (including WordPress admin credentials, 2FA secrets, database and email credentials) and remote file-writing capabilities, potentially allowing further site compromise and data exfiltration. WooCommerce order data including payment methods from the past three months was also exposed. This could lead to unauthorized access, data breaches, and site manipulation on affected WordPress installations.
Mitigation Recommendations
Official patches are available: update Product Slider Pro to version 3.5.4 or later, Real Testimonials Pro to 3.2.6 or later, and Smart Post Show Pro to 4.0.2 or later. The vendor has confirmed investigation and mitigation measures. If infected fake WooCommerce plugins are detected, administrators should reset all WordPress passwords, regenerate two-factor authentication secrets, and review user accounts for unauthorized additions. No further action is required beyond applying these updates and following these recommendations.
ShapedPlugin update flow hacked to infect WordPress sites
Description
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system. [...]
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ShapedPlugin's build pipeline was compromised, allowing attackers to inject a malicious loader (LicenseLoader.php) into three paid WordPress plugins. When an administrator accessed the WordPress admin panel, the loader contacted a command-and-control server to download a backdoor disguised as a fake WooCommerce plugin. This backdoor was hidden from the plugin list and stole WordPress login credentials, 2FA secrets, database credentials, SMTP credentials, and recent WooCommerce order data. The attack was confirmed by Wordfence and tracked under CVE-2026-10735 (with a duplicate CVE-2026-49777). The vendor released fixed versions: Product Slider Pro 3.5.4, Real Testimonials Pro 3.2.6, and Smart Post Show Pro 4.0.2. The compromise appears limited to the vendor's release infrastructure, as WordPress.org hosted releases were clean.
Potential Impact
The supply chain compromise allowed attackers to distribute malware to paying customers via official plugin updates. The malware enabled credential theft (including WordPress admin credentials, 2FA secrets, database and email credentials) and remote file-writing capabilities, potentially allowing further site compromise and data exfiltration. WooCommerce order data including payment methods from the past three months was also exposed. This could lead to unauthorized access, data breaches, and site manipulation on affected WordPress installations.
Mitigation Recommendations
Official patches are available: update Product Slider Pro to version 3.5.4 or later, Real Testimonials Pro to 3.2.6 or later, and Smart Post Show Pro to 4.0.2 or later. The vendor has confirmed investigation and mitigation measures. If infected fake WooCommerce plugins are detected, administrators should reset all WordPress passwords, regenerate two-factor authentication secrets, and review user accounts for unauthorized additions. No further action is required beyond applying these updates and following these recommendations.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/shapedplugin-update-flow-hacked-to-infect-wordpress-sites/","fetched":true,"fetchedAt":"2026-06-18T13:05:05.295Z","wordCount":869}
Threat ID: 6a33ed01f198dc38c1d63eab
Added to database: 6/18/2026, 1:05:05 PM
Last enriched: 6/18/2026, 1:05:19 PM
Last updated: 6/19/2026, 3:06:46 PM
Views: 36
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.