CVE Tools
Back to feed
Exploited in the wild Product Slider Pro supply-chain Real Testimonials Pro ShapedPlugin web-app

ShapedPlugin update flow hacked to infect WordPress sites

BleepingComputer·By Bill Toulas··3 min read
CVE Tools coverage

ShapedPlugin says multiple of its WordPress plugins were compromised in a supply-chain attack that inserted malicious code into legitimate releases delivered through the vendor’s official update mechanism. The affected paid plugins are Product Slider Pro before 3.5.4 for WooCommerce, Real Testimonials Pro 3.2.5, and Smart Post Show Pro before 4.0.2, where attackers used backdoored builds to steal credentials and enable remote file-writing via impersonated WooCommerce components. WordPress tracking for this incident includes CVE-2026-10735 (with CVE-2026-49777 submitted as a duplicate), highlighting why updating from trusted channels can still be risky when build pipelines are compromised.