INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShapedPlugin WordPress Exploit in Supply Chain

| 2026-06-22 18:00 CRITICAL MEDIUM
Executive Summary AI-generated
The supply chain compromise affecting ShapedPlugin's WordPress plugins has been identified as a critical incident with maximum severity. The compromised versions of the affected plugins, including Product Slider Pro for WooCommerce and Real Testimonials Pro, incorporate a loader that triggers on every admin page to fetch a payload from a remote server, leading to potential data breaches and unauthorized access. This exploit leverages vulnerabilities in software versions listed by ShapedPlugin as being impacted, with CVE identifiers assigned by the Mitre ATT&CK technique of "Loader" and "Remote File Inclusion". The incident has been reported to ShapedPlugin, which is reviewing its distribution and release processes to ensure product integrity moving forward.
Technical Mitigations AI-generated
* Implement a secure update mechanism that verifies the authenticity of updates before installing them, and only allows installations from trusted sources. * Use a Content Security Policy (CSP) to restrict the types of scripts and stylesheets that can be executed on WordPress sites, and ensure that all plugins are properly sanitized and validated before installation. * Regularly review and update WordPress core and plugin dependencies to prevent known vulnerabilities being exploited by attackers. * Consider using a Web Application Firewall (WAF) or an Intrusion Detection System (IDS) to detect and respond to potential security threats on WordPress sites.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-49777CVE-2026-49777 CVE-2026-10735CVE-2026-10735
Target & Sectors
NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎May 21
ShapedPlugin's Pro builds were compromised on May 21 through a supply chain attack.
organisation ShapedPlugin
organisation Wordfence
‎June 10
ShapedPlugin's Pro plugins were compromised in a supply chain attack on May 21.
organisation ShapedPlugin
organisation Wordfence
‎June 12
Researchers confirmed the breach on June 12 after downloading infected plugins from ShapedPlugin.
‎2026/06/15
Threat actors used a supply chain attack to inject backdoor code into ShapedPlugin WordPress Pro Plugins.
‎June 16
The researchers discovered the breach on June 16 after downloading infected plugins from the ShapedPlugin site.
‎Jun 22, 2026
The ShapedPlugin compromised versions of Product Slider Pro for WooCommerce, Real Testimonials Pro and Smart Post Show Pro exploit a supply chain attack by loading malicious code on every admin page.
infrastructure 3.5.4
infrastructure 3.2.5
infrastructure 4.0.2
organisation Smart Post Show Pro
organisation Easy Digital Downloads
organisation EDD
organisation Product Slider Pro for WooCommerce
organisation CVE
organisation CVE-2026
organisation CVSS
infrastructure 194.76.217
organisation WordPress
organisation PHP
organisation WP Mail SMTP
organisation WooCommerce
organisation WordPress.org
organisation ShapedPlugin
‎2026/06/22
Threat actors used a fake plugin to backdoor ShapedPlugin WordPress Pro Plugins in supply chain attack.
infrastructure 3.5.4
infrastructure 4.0.2
organisation Smart Post Show Pro
organisation CVE-2026
organisation WordPress
organisation IP
organisation SMTP
organisation WooCommerce
organisation ShapedPlugin WordPress
organisation Multiple WordPress
organisation WordPress.org
infrastructure 3.2.6
organisation BleepingComputer
organisation Wordfence
organisation UI
organisation OptinMonster
organisation CDN
organisation EDR
Tactical Metrics
Metrics
infrastructure
‎3.5.4
Software Version
Metrics
infrastructure
‎3.2.5
Software Version
Metrics
infrastructure
‎4.0.2
Software Version
Metrics
infrastructure
‎194.76.217
Software Version
Metrics
infrastructure
‎3.2.6
Software Version
Intelligence Sources
BleepingComputer 2026-06-18