CVE Tools
Back to feed
Exploited in the wild Pro plugin releases supply-chain ShapedPlugin data-breach

ShapedPlugin Supply Chain Attack Exposes WordPress Sites

Daily CyberSecurity (securityonline.info)·By Do Son··3 min read
CVE Tools coverage

Researchers say a ShapedPlugin supply chain attack compromised the vendor’s distribution pipeline and inserted malicious backdoor code into premium Pro plugin releases, impacting WordPress sites that update normally. The activity is tracked under CVE-2026-10735 and CVE-2026-49777, with confirmed exposure including Real Testimonials Pro version 3.2.5 plus other premium plugins such as Product Slider Pro and Smart Post Pro. This matters because the malware also targets authentication (including 2FA/TOTP secrets), potentially allowing attackers to bypass multi-factor protections.