ShapedPlugin update flow hacked to infect WordPress sites
Reported exploitedProduct Slider ProReal Testimonials ProOur summary
ShapedPlugin says multiple of its WordPress plugins were compromised in a supply-chain attack that inserted malicious code into legitimate releases delivered through the vendor’s official update mechanism. The affected paid plugins are Product Slider Pro before 3.5.4 for WooCommerce, Real Testimonials Pro 3.2.5, and Smart Post Show Pro before 4.0.2, where attackers used backdoored builds to steal credentials and enable remote file-writing via impersonated WooCommerce components. WordPress tracking for this incident includes CVE-2026-10735 (with CVE-2026-49777 submitted as a duplicate), highlighting why updating from trusted channels can still be risky when build pipelines are compromised.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.