CVE-2026-10735
ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
Description
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:NAvailabilityExploitability
References
- ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attacken·The Hacker News· Exploited Product Slider Pro for WooCommerce supply-chain
- ShapedPlugin update flow hacked to infect WordPress sitesen-us·BleepingComputer· Exploited Product Slider Pro supply-chain
- ShapedPlugin Supply Chain Attack Exposes WordPress Sitesen-us·Daily CyberSecurity (securityonline.info)· Exploited Pro plugin releases supply-chain
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-10735 and every CVE in our database. Create a free account — no credit card required.
Create Free Account