CyberSecurityBoardThreat Intel · CVEs · Products
Malware

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

June 25, 2026

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors tampered with the official release channels and pushed backdoor code. According to Wordfence, attackers compromised the vendor’s build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels.

The incident affects the following plugins: Product Slider Pro for WooCommerce (versions before 3.5.4), Real Testimonials Pro (version 3.2.5), and Smart Post Show Pro (versions before 4.0.2). The compromise only affects Pro plugin builds distributed through the vendor’s Easy Digital Downloads (EDD) infrastructure via account.shapedplugin[.]com. Free versions on WordPress.org are not impacted.

The supply chain compromise associated with Product Slider Pro for WooCommerce has been assigned CVE-2026-49777 with a CVSS score of 10.0. CVE-2026-10735 (CVSS 9.8) is the identifier for the entire incident. The compromised plugins incorporate a loader triggered on every admin page, fetching a payload from a remote server, installing it, and activating it as a fake plugin. The malware reports the victim domain back to the server and erases itself to cover tracks.

The counterfeit plugin hides from the WordPress admin plugin list, captures credentials in plaintext and two-factor authentication (2FA) codes, establishes multiple persistence methods, enables arbitrary file writes via a custom REST endpoint, and drops a web shell with command execution features. It also extracts data including wp-config.php contents, administrator accounts, mail plugin credentials, and WooCommerce order data.

Evidence indicates the attack compromised the build pipeline rather than direct package poisoning. ShapedPlugin has confirmed the incident and is reviewing distribution and release processes. New plugin versions are expected after comprehensive security reviews. Site owners who installed malicious versions should reset all passwords, revoke 2FA secrets, review administrator accounts, and check mail plugin configurations.

CVEs: CVE-2026-49777, CVE-2026-10735, CVE-2026-11645

Companies: ShapedPlugin, Wordfence

Products: Product Slider Pro for WooCommerce, Real Testimonials Pro, Smart Post Show Pro, Easy Digital Downloads