Close Menu
    What's Hot

    The 16 Best Amazon Prime Day Deals Under $30 We’ve Found

    England 0 – 0 Ghana

    Harriet Dart bows out of Eastbourne Open as Arthur Fery among six Brits to make history at Wimbledon tune-up event | Tennis News

    Facebook X (Twitter) Instagram
    Trending
    • The 16 Best Amazon Prime Day Deals Under $30 We’ve Found
    • England 0 – 0 Ghana
    • Harriet Dart bows out of Eastbourne Open as Arthur Fery among six Brits to make history at Wimbledon tune-up event | Tennis News
    • 2026 NBA Mock Draft: Gary Parrish’s final projections following Giannis Antetokounmpo blockbuster trade
    • The World’s Safest and Most Dangerous Countries in 2026
    • Domino’s gets a new CEO amid slowing sales—but is it enough to save pizza chains?
    • Paraguay’s Almiron suspended for one game after red card for covering mouth | World Cup 2026
    • U.S. Presses Meta to Agree to A.I. Reviews
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

    adminBy adminJune 22, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 22, 2026Supply Chain Attack / Malware

    ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

    Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code.

    “Attackers compromised the vendor’s build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels,” Wordfence said in an analysis published last week.

    The incident affects the following plugins –

    • Product Slider Pro for WooCommerce (versions before 3.5.4)
    • Real Testimonials Pro (version 3.2.5)
    • Smart Post Show Pro (versions before 4.0.2)

    As mentioned above, it’s worth emphasizing that the compromise only affects Pro plugin builds distributed through the vendor’s Easy Digital Downloads (EDD) infrastructure via account.shapedplugin[.]com. The free versions of the plugins on WordPress.org are not impacted.

    Cybersecurity

    The supply chain compromise associated with Product Slider Pro for WooCommerce has been assigned the CVE identifier CVE-2026-49777, along with a CVSS score of 10.0, indicating maximum severity. CVE-2026-10735 (CVSS score: 9.8) is the CVE identifier for the entire incident.

    The WordPress security company said the compromised versions of the plugins incorporate a loader that’s triggered on every admin page, causing it to fetch a payload from a remote server (“194.76.217[.]28:2871”), install it, and activate it as a fake plugin.

    Once it’s activated, the malware reports the victim domain back to the server and erases itself to cover up the tracks and complicate incident response efforts. The counterfeit plugin, for its part, hides itself from the WordPress admin plugin list and is capable of capturing credentials in plaintext and two-factor authentication (2FA) codes.

    It also establishes multiple persistence methods that enable arbitrary file writes via a custom REST endpoint when provided a specific authentication token, as well as drop a web shell with command execution features. Lastly, it makes use of a PHP file named “install-persistent.php,” which is bundled as part of the plugin, to extract the below data –

    • Full contents of wp-config.php, including database credentials, authentication keys, and debug settings
    • All administrator accounts with registration dates
    • Mail plugin credentials from WP Mail SMTP, Post SMTP, and Easy WP SMTP
    • WooCommerce order data from the last 3 months with payment method breakdown

    Once this information is displayed, the file is deleted. Evidence indicates that the attack could be a compromise of the build pipeline, as opposed to a direct poisoning of the packages.

    Cybersecurity

    What’s particularly dangerous about this attack is that it exposes site owners who purchased legitimate licenses and installed updates directly from the vendor’s official update system to malware.

    Upon being notified of the issue, ShapedPlugin has confirmed the incident, adding that it’s reviewing the distribution and release processes to ensure the integrity of its products going forward. New versions of the impacted plugins are expected to be released pending comprehensive security reviews and validation tests.

    Site owners who have installed the malicious versions are recommended to reset all passwords, revoke and regenerate 2FA secrets for all users, review administrator accounts for unauthorized additions, and check mail plugin configurations for modified SMTP credentials.

    attack Backdoored Chain plugins Pro ShapedPlugin Supply Wordpress
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleTraveling with Sleep Apnea: Expert Recommendations for…
    Next Article Lionel Messi breaks World Cup goals record with 17th strike
    admin
    • Website

    Related Posts

    FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

    June 23, 2026

    Trump Order Sets 2030 Deadline for Federal Post-Quantum Crypto Migration

    June 23, 2026

    Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26,000 Agents

    June 23, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    The 16 Best Amazon Prime Day Deals Under $30 We’ve Found

    England 0 – 0 Ghana

    Harriet Dart bows out of Eastbourne Open as Arthur Fery among six Brits to make history at Wimbledon tune-up event | Tennis News

    2026 NBA Mock Draft: Gary Parrish’s final projections following Giannis Antetokounmpo blockbuster trade

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by