CVE Tools
Back to feed
Exploited in the wild Product Slider Pro for WooCommerce supply-chain Real Testimonials Pro ShapedPlugin malware

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

ShapedPlugin says multiple WordPress Pro plugins were backdoored in a supply chain incident after attackers tampered with its official release and licensed update distribution. The affected plugins are Product Slider Pro for WooCommerce (versions before 3.5.4), Real Testimonials Pro (version 3.2.5), and Smart Post Show Pro (versions before 4.0.2), delivered through ShapedPlugin’s Easy Digital Downloads (EDD) infrastructure at account.shapedplugin[.]com—while free versions on WordPress.org were not impacted. Security researchers link the incident to CVE-2026-10735 (CVSS 9.8) and CVE-2026-49777 (CVSS 10.0), highlighting the risk to legitimate license holders via trusted vendor updates and the potential for credential theft and persistence.