ShapedPlugin’s official update system was compromised and pushed malware-tainted WordPress plugin updates to paying customers, putting affected websites at risk of credential theft and remote tampering. WordPress is tracking the incident as CVE-2026-10735. Affected paid plugins were Product Slider Pro before 3.5.4 for WooCommerce, Real Testimonials Pro 3.2.5, and Smart Post Show Pro before 4.0.2; Wordfence says the malicious code acted as a loader that fetched a second-stage backdoor, hid it as fake WooCommerce plugins, and stole admin logins, two-factor authentication secrets, database credentials, and recent WooCommerce order data.
Why it matters: Website owners who installed these paid plugin updates may have had their WordPress and store credentials stolen and their sites quietly backdoored. Affected admins should update immediately, look for the fake WooCommerce plugins, rotate passwords and keys, and review their sites for unauthorized changes.
info@thehackernews.com (The Hacker News)
2026.06.22
99% relevant
The article covers the same underlying event: ShapedPlugin's official update channel for paid WordPress plugins was compromised and delivered backdoored updates to customer sites.
Bill Toulas
2026.06.18
100% relevant
This article establishes a distinct new supply-chain incident centered on ShapedPlugin’s compromised release infrastructure and malware delivered through official paid plugin updates.
← Back to all stories