CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-10735: Supply Chain Compromise of ShapedPlugin WordPress Plugins

June 25, 2026

CVE-2026-10735 is a high-severity vulnerability (CVSS 9.8) covering the entire supply chain incident affecting multiple ShapedPlugin Pro plugins. Attackers compromised the vendor's build pipeline to distribute backdoored updates.