Shapedplugin wordpress pro - ```json "title": "shapedplugin wordpress plugins

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

“`json
{
“title”: “ShapedPlugin WordPress Pro Plugins Hit by Supply Chain Attack”,
“slug”: “shapedplugin-wordpress-pro-plugins-supply-chain-attack”,
“meta_description”: “ShapedPlugin WordPress Pro plugins were compromised in a supply chain attack. Backdoor code was injected through official update channels affecting three plugins.”,
“keywords”: [“WordPress supply chain attack”, “ShapedPlugin backdoor”, “WordPress plugin security”, “CVE-2026-10735”, “WordPress malware”],
“primary_keyword”: “WordPress supply chain attack”,
“content”: “

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after threat actors infiltrated the official release channels. The attackers injected backdoor code into Pro versions of three popular plugins, affecting thousands of website owners who trusted the vendor’s official update system.

Wordfence, a leading WordPress security firm, discovered that attackers compromised ShapedPlugin’s build and distribution pipeline. The malicious code was pushed through licensed update channels, targeting customers who purchased legitimate licenses. This attack demonstrates how even authorized distribution systems can become vectors for malware distribution.

Affected WordPress Plugins and Versions

The supply chain attack impacted three ShapedPlugin Pro products distributed through the vendor’s Easy Digital Downloads infrastructure. Product Slider Pro for WooCommerce version 3.5.2 was compromised, along with Real Testimonials Pro versions 3.2.4 and 3.2.5. Additionally, Smart Post Show Pro version 4.0.1 contained the backdoor code.

The free versions available on WordPress.org remained unaffected by this attack. Only Pro builds distributed through account.shapedplugin.com contained the malicious code. This distinction is important because many users assume official vendor channels are inherently secure.

Security researchers assigned CVE-2026-10735 to track this vulnerability, which received a critical CVSS score of 9.8. An earlier identifier, CVE-2026-49777, was later marked as a duplicate of the primary designation.

How the WordPress Backdoor Functions

The compromised plugin versions included a loader that activated on every WordPress admin page. This loader connected to a remote server at IP address 194.76.217.28 on port 2871 to fetch additional malicious payloads. Once retrieved, the malware installed itself as a counterfeit plugin before erasing traces of the initial infection.

The fake plugin operated under the name “WooCommerce Subscription,” mimicking the legitimate WooCommerce Subscriptions extension. However, this malicious version concealed itself from the standard WordPress plugin list. The backdoor captured administrator credentials in plaintext, including two-factor authentication codes.

Furthermore, the malware established multiple persistence mechanisms across infected sites. It created a custom REST endpoint that allowed arbitrary file writes when provided with a specific authentication token. The attackers also deployed a web shell with command execution capabilities, giving them complete control over compromised websites.

Data Theft and Information Extraction

ShapedPlugin’s security advisories revealed that the malware targeted sensitive configuration data. The backdoor injected a loader into the active theme’s functions.php file, which executed a Base64-encoded payload on every page load. This payload systematically extracted critical information from infected WordPress installations.

The stolen data included complete wp-config.php contents with database credentials and authentication keys. All administrator accounts were compromised along with their registration dates. Mail plugin credentials from WP Mail SMTP, Post SMTP, and Easy WP SMTP were also captured.

Additionally, the malware extracted WooCommerce order data from the previous three months. This information included payment method breakdowns, potentially exposing customer transaction details. After displaying this information in an HTML page, the malware deleted itself to complicate forensic analysis.

Supply Chain Attack Vector Analysis

Wordfence investigators concluded that the attack originated from a compromise of ShapedPlugin’s build and distribution pipeline. This assessment suggests the attackers gained access to the vendor’s development or deployment systems. Therefore, the malicious code was automatically included in legitimate plugin packages during the build process.

ShapedPlugin characterized the incident as tampering with Pro builds distributed through its Easy Digital Downloads update channel. The timing of the attack proved particularly concerning. Real Testimonials Pro version 3.2.5 initially shipped clean on May 23, 2026, but was subsequently tampered with under the same version number.

This revelation highlights a critical security issue: version numbers alone cannot verify package integrity. Consequently, even users who carefully track version updates may have installed compromised code without knowing it.

Official Response and Security Measures

ShapedPlugin responded quickly after discovering the breach. The company released clean versions for all affected plugins, including Product Slider Pro for WooCommerce 3.5.3 and Real Testimonials Pro 3.2.6. Smart Post Show Pro received version 4.0.2 initially, with subsequent updates reaching version 4.0.5.

The Wilmington-based company implemented comprehensive security improvements. It rotated all credentials and took the affected distribution infrastructure offline for rebuilding. Additionally, ShapedPlugin discontinued its GitHub-based release workflow pending a complete security redesign.

The vendor migrated product files to isolated AWS infrastructure and moved its technology stack to an xCloud-managed VPS. Patchstack monitoring was added for continuous security oversight. ShapedPlugin also proactively notified all customers who downloaded an affected build.

Remediation Steps for Affected Sites

Both ShapedPlugin and Wordfence emphasized that updating alone does not remove the second-stage payload. Sites that installed affected versions require complete cleanup procedures. Simply installing the clean plugin version leaves the backdoor code active on compromised websites.

Site administrators should immediately reset all user passwords and revoke existing two-factor authentication secrets. Review administrator accounts for unauthorized additions that attackers may have created. Check for the fake “WooCommerce Subscription” plugin and remove it if present.

Examine the active theme’s functions.php file for malicious loader code. Additionally, verify mail plugin configurations haven’t been modified with unauthorized SMTP credentials. ShapedPlugin published detailed per-product advisories with step-by-step remediation instructions for each affected plugin.

Broader Implications for WordPress Security

This incident reveals significant vulnerabilities in the WordPress plugin ecosystem. Site owners who purchased legitimate licenses and followed best practices by installing official updates still fell victim to malware. The attack undermines trust in vendor-controlled distribution channels that users typically consider secure.

Security experts note that supply chain attacks represent an increasingly common threat vector. Attackers who compromise a single vendor can potentially infect thousands of downstream users simultaneously. This multiplier effect makes supply chain compromises particularly attractive to threat actors.

ShapedPlugin confirmed it found no evidence that customer data from its own systems was accessed. However, the data-theft functionality clearly targeted end-user sites that installed the tampered builds. This distinction is important for understanding the attack’s full scope and impact.

The incident serves as a reminder that WordPress site owners must implement defense-in-depth strategies. Regular backups, file integrity monitoring, and security plugins provide additional protection layers. Even when using trusted vendors, vigilance remains essential for maintaining website security in today’s threat landscape.

“,
“excerpt”: “ShapedPlugin’s WordPress Pro plugins were compromised in a supply chain attack affecting Product Slider Pro, Real Testimonials Pro, and Smart Post Show Pro. Attackers injected backdoor code through official update channels, stealing credentials and site data.”,
“image_alt_suggestion”: “WordPress plugin security warning showing ShapedPlugin supply chain attack affecting Pro versions”,
“internal_link_suggestions”: [“WordPress plugin security best practices”, “supply chain attack prevention”, “WordPress malware removal guide”, “two-factor authentication WordPress”, “WooCommerce security hardening”]
}
“`

Original Source: thehackernews.com

Leave a Comment





This site uses Akismet to reduce spam. Learn how your comment data is processed.