CVE-2026-49777: Critical Supply Chain Vulnerability in Product Slider Pro for WooCommerce
CVE-2026-49777 is a critical vulnerability in the Product Slider Pro for WooCommerce plugin from ShapedPlugin, with a CVSS score of 10.0. It…
CVE-2026-49777 is a critical vulnerability in the Product Slider Pro for WooCommerce plugin from ShapedPlugin, with a CVSS score of 10.0. It…
CVE-2026-10735 is a high-severity vulnerability (CVSS 9.8) covering the entire supply chain incident affecting multiple ShapedPlugin Pro plugins. Attackers compromised the vendor's…
ShapedPlugin is a WordPress plugin vendor whose Pro plugins were backdoored in a supply chain attack. The company confirmed the incident and…
Product Slider Pro for WooCommerce, a ShapedPlugin plugin, was compromised in a supply chain attack. Versions before 3.5.4 contain backdoor code injected…
Real Testimonials Pro version 3.2.5 from ShapedPlugin was compromised in a supply chain attack, with backdoor code injected into the official update…
Smart Post Show Pro versions before 4.0.2 from ShapedPlugin were backdoored in a supply chain attack, impacting users who installed updates from…
Easy Digital Downloads (EDD) is the platform used by ShapedPlugin to distribute Pro plugins. The supply chain attack compromised the EDD infrastructure…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…