CVE Tools

ShapedPlugin update flow hacked to infect WordPress sites

BleepingComputerBy Bill Toulas

Reported exploitedProduct Slider ProReal Testimonials Pro

Our summary

ShapedPlugin says multiple of its WordPress plugins were compromised in a supply-chain attack that inserted malicious code into legitimate releases delivered through the vendor’s official update mechanism. The affected paid plugins are Product Slider Pro before 3.5.4 for WooCommerce, Real Testimonials Pro 3.2.5, and Smart Post Show Pro before 4.0.2, where attackers used backdoored builds to steal credentials and enable remote file-writing via impersonated WooCommerce components. WordPress tracking for this incident includes CVE-2026-10735 (with CVE-2026-49777 submitted as a duplicate), highlighting why updating from trusted channels can still be risky when build pipelines are compromised.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store