ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Reported exploitedProduct Slider Pro for WooCommerceReal Testimonials ProOur summary
ShapedPlugin says multiple WordPress Pro plugins were backdoored in a supply chain incident after attackers tampered with its official release and licensed update distribution. The affected plugins are Product Slider Pro for WooCommerce (versions before 3.5.4), Real Testimonials Pro (version 3.2.5), and Smart Post Show Pro (versions before 4.0.2), delivered through ShapedPlugin’s Easy Digital Downloads (EDD) infrastructure at account.shapedplugin[.]com—while free versions on WordPress.org were not impacted. Security researchers link the incident to CVE-2026-10735 (CVSS 9.8) and CVE-2026-49777 (CVSS 10.0), highlighting the risk to legitimate license holders via trusted vendor updates and the potential for credential theft and persistence.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.