A particularly serious supply chain attack has once again highlighted the risks facing the WordPress. ShapedPlugin has confirmed that multiple of its commercial plugins were compromised, resulting in the distribution of infected updates to subscribers via the company's official update mechanism.

The incident is particularly concerning, as ShapedPlugin is a well-known WordPress plugin vendor, with over 400,000 active installations of its free products. While the attack did not affect the company’s entire portfolio, it demonstrates that even trusted software vendors can be turned into vehicles for distributing malicious code.
ShapedPlugin: Which plugins were affected?
According to the information so far, the breach was limited to three of the company's paid plugins. These are Product Slider Pro before version 3.5.4, Real Testimonials Pro 3.2.5 , and Smart Post Show Pro before version 4.0.2.
These plugins are widely used by online stores and professional websites to display products, manage customer testimonials, and present content. Because of this use, the potential impact of the attack extends beyond simply compromising a website and can affect customer data, order details, and management information.
See also: CISA: Vulnerability in LiteSpeed cPanel Plugin allows privilege escalation
How the attack worked
Researchers at Defiant, the company behind Wordfence, found that the infected packages contained a malicious loader file called LicenseLoader.php. This file was triggered when an administrator logged into the WordPress admin panel.
It then communicated with a remote command and control (C2) server, from which it downloaded second stage malware. The backdoor was installed as a fake plugin with names like “woocommerce-subscription” or “woocommerce-notification” to make it look like a legitimate WooCommerce component.
The most worrying element is that the fake plugin remained hidden from the list of installed plugins, making it particularly difficult for website administrators to detect.

The data targeted by the attackers
The investigation revealed that the backdoor was designed to collect an impressively large amount of sensitive information. This included administrator usernames and passwords, login cookies, IP addresses, browser details, two-factor authentication keys, database credentials, and WordPress security keys.
At the same time, the attackers targeted administrator account details, service credentials , and WooCommerce order data from the last three months, including information about payment methods.
If successfully exploited, attackers could gain full access to a website, steal customer data, redirect payments, or even use the server to carry out additional attacks.
See also: Vulnerability in Kirki Plugin puts WordPress sites at risk
The breach appears to have started during the plugin creation process
Data collected by Wordfence shows that the backdoor was introduced in Pro versions on May 21, while the first reports of suspicious updates appeared on June 10. Researchers confirmed the breach on June 12, while ShapedPlugin officially acknowledged the incident four days later.
Experts believe the point of breach was the plugin creation and distribution. Timestamp patterns, file modifications, and Git references suggest automated malicious code insertion during the update release process.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Most importantly, the plugin releases hosted on WordPress.org were confirmed to be secure. This means that the attackers gained access to ShapedPlugin's release infrastructure and not the official WordPress repository.

What webmasters should do
The incident is now being tracked with the identifier CVE-2026-10735 and ShapedPlugin has already released fixes for the affected plugins.
Security experts recommend that administrators look for the existence of fake WooCommerce plugins, reset all administrator passwords, create new two-factor authentication (2FA) secrets, and carefully check the user list for unauthorized accounts.
See also: JetBrains Plugins: 15 malicious plugins steal AI API keys
The ShapedPlugin case is yet another reminder that supply chain attacks are emerging as one of the biggest threats to modern cybersecurity. When a trusted supplier is compromised, thousands of websites can be exposed simultaneously, demonstrating that trust in software must now be accompanied by constant monitoring and rigorous security practices.
Source: www.bleepingcomputer.com
