Exploited in the wild Pro plugin releases supply-chain ShapedPlugin data-breach
ShapedPlugin Supply Chain Attack Exposes WordPress Sites
CVE Tools coverage
Researchers say a ShapedPlugin supply chain attack compromised the vendor’s distribution pipeline and inserted malicious backdoor code into premium Pro plugin releases, impacting WordPress sites that update normally. The activity is tracked under CVE-2026-10735 and CVE-2026-49777, with confirmed exposure including Real Testimonials Pro version 3.2.5 plus other premium plugins such as Product Slider Pro and Smart Post Pro. This matters because the malware also targets authentication (including 2FA/TOTP secrets), potentially allowing attackers to bypass multi-factor protections.