CVE Tools

ShapedPlugin Supply Chain Attack Exposes WordPress Sites

Daily CyberSecurity (securityonline.info)By Do Son

Reported exploitedPro plugin releasesShapedPlugin

Our summary

Researchers say a ShapedPlugin supply chain attack compromised the vendor’s distribution pipeline and inserted malicious backdoor code into premium Pro plugin releases, impacting WordPress sites that update normally. The activity is tracked under CVE-2026-10735 and CVE-2026-49777, with confirmed exposure including Real Testimonials Pro version 3.2.5 plus other premium plugins such as Product Slider Pro and Smart Post Pro. This matters because the malware also targets authentication (including 2FA/TOTP secrets), potentially allowing attackers to bypass multi-factor protections.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store