CVE-2026-10735 is a high-severity vulnerability (CVSS 9.8) covering the entire supply chain incident affecting multiple ShapedPlugin Pro plugins. Attackers compromised the vendor's…
Product Slider Pro for WooCommerce, a ShapedPlugin plugin, was compromised in a supply chain attack. Versions before 3.5.4 contain backdoor code injected…
CVE-2026-49777Product Slider Pro for WooCommercesupply chain attackWooCommerce
Easy Digital Downloads (EDD) is the platform used by ShapedPlugin to distribute Pro plugins. The supply chain attack compromised the EDD infrastructure…
Cybersecurity researchers at JFrog have uncovered a set of malicious npm packages that masquerade as legitimate PostCSS tools to deliver a Windows-based…