{"id":57075,"date":"2026-06-18T09:23:34","date_gmt":"2026-06-18T13:23:34","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=57075"},"modified":"2026-06-18T09:23:34","modified_gmt":"2026-06-18T13:23:34","slug":"shapedplugin-supply-chain-attack-wordpress-backdoor","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/shapedplugin-supply-chain-attack-wordpress-backdoor\/","title":{"rendered":"ShapedPlugin supply chain attack injects backdoor into WordPress plugins"},"content":{"rendered":"<p>Multiple commercial WordPress plugins distributed by <a href=\"https:\/\/shapedplugin.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">ShapedPlugin<\/a> were compromised in a sophisticated <a href=\"https:\/\/overcentral.com\/en\/wordpress-supply-chain-attack-optinmonster\/\" title=\"Supply-chain attack hits OptinMonster plugin on 1.2 million WordPress sites\" data-iacss-internal=\"1\">supply chain attack<\/a> that pushed backdoored releases to paying customers through the vendor&#8217;s official update mechanism. The malware, delivered as fake WooCommerce components, establishes persistent remote access, steals administrative credentials, and exfiltrates sensitive e-commerce data. The incident underscores a growing trend of attackers targeting plugin build pipelines rather than exploiting individual site vulnerabilities.<\/p>\n<h2>What the ShapedPlugin Supply Chain Attack Entails<\/h2>\n<p>ShapedPlugin, a vendor specializing in front-end UI and content display plugins with over 400,000 active free installations, confirmed that three paid products were affected: Product Slider Pro for WooCommerce (prior to version 3.5.4), Real Testimonials Pro (version 3.2.5), and Smart Post <a href=\"https:\/\/overcentral.com\/en\/grow-up-show-sunflower-circus-trailers\/\" title=\"GROW UP SHOW: Sunflower Circus Drops Main Visual and Trailers Before July 4 Premiere\" data-iacss-internal=\"1\">Show<\/a> Pro (prior to version 4.0.2). Security researchers at <a href=\"https:\/\/www.wordfence.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Wordfence<\/a> identified that the backdoor was injected into ShapedPlugin&#8217;s Pro builds on May 21, with the first customer reports surfacing on June 10. The breach was confirmed after researchers downloaded infected plugins directly from the ShapedPlugin site on <a href=\"https:\/\/overcentral.com\/en\/evangelion-sanrio-plush-june-12-japan\/\" title=\"Evangelion x Sanrio Plush Drops June 12 in Japan\" data-iacss-internal=\"1\">June 12<\/a>, and the vendor acknowledged the incident on June 16.<\/p>\n<h2>How the Backdoor Operates on Infected Sites<\/h2>\n<p>The compromised plugins contain a malicious loader file named LicenseLoader.php that activates when a WordPress administrator accesses the admin panel. The loader contacts a command-and-control server, downloads a second-stage backdoor, and installs it as a fake plugin disguised as woocommerce-subscription or woocommerce-notification. This fake plugin is deliberately hidden from the WordPress plugin list and self-deletes after execution to erase forensic evidence. The backdoor grants attackers remote file-writing capabilities, enabling persistent control over the compromised environment.<\/p>\n<h2>What Data Was Targeted in This Supply Chain Attack<\/h2>\n<p>The implanted backdoor was configured to harvest a broad range of sensitive information from infected WordPress sites, including WordPress login credentials (usernames, passwords, session cookies, user roles, IP addresses, and browser details), two-factor authentication secrets from popular WordPress security plugins, database credentials and authentication keys from wp-config.php, administrator account details, SMTP and email service credentials, and WooCommerce order data from the preceding three months, including payment method information. This level of access would allow attackers to fully compromise the affected site, pivot to connected services, and steal customer financial data.<\/p>\n<h2>How the Compromise Occurred and Current Remediation Status<\/h2>\n<p>Researchers attribute the breach to a build pipeline compromise based on file modification patterns, timestamp sequences suggesting automated injection, and Git build references inside the packages. Notably, the free versions hosted on WordPress.org remained clean, indicating that the attackers gained access specifically to ShapedPlugin&#8217;s proprietary release infrastructure. The incident is tracked under CVE-2026-10735, with CVE-2026-49777 submitted as a duplicate. Patched releases are available: Product Slider Pro version 3.5.4, Real Testimonials Pro version 3.2.6, and Smart Post Show Pro version 4.0.2. ShapedPlugin has stated that an official confirmation will follow once Wordfence validates that the patches fully resolve the issue.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Administrators who use any of the affected ShapedPlugin Pro plugins should immediately update to the latest patched versions. If any instance of a fake WooCommerce plugin (woocommerce-subscription or woocommerce-notification) is discovered, all passwords on the site should be reset, all two-factor authentication secrets should be regenerated, and user lists must be audited for unauthorized accounts. Given the credential-theft capabilities of this backdoor, any services that share passwords with the compromised WordPress environment should be treated as potentially exposed. Organizations managing multiple sites should review their update infrastructure and consider implementing integrity verification steps for vendor-supplied plugin packages. This attack is a reminder that supply chain risks extend beyond open-source repositories and require scrutiny of commercial plugin distribution channels as well.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple commercial WordPress plugins distributed by ShapedPlugin were compromised in a sophisticated supply chain attack that pushed backdoored releases to paying customers through the vendor&#8217;s official update mechanism. The malware, delivered as fake WooCommerce components, establishes persistent remote access, steals administrative credentials, and exfiltrates sensitive e-commerce data. The incident underscores a growing trend of attackers [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":73904,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/CxAdEWN.jpg","fifu_image_alt":"ShapedPlugin supply chain attack injects backdoor into WordPress plugins","footnotes":""},"categories":[349],"tags":[],"class_list":["post-57075","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/CxAdEWN.jpg","fifu_image_alt":"ShapedPlugin supply chain attack injects backdoor into WordPress plugins","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57075","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=57075"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57075\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/73904"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=57075"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=57075"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=57075"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}