# Critical Supply Chain Attack Backdoors WordPress Plugins From ShapedPlugin


## The Threat


ShapedPlugin's WordPress Pro plugins have been compromised in a sophisticated supply chain attack that injected malicious code directly into the vendor's official distribution pipeline. Unknown threat actors gained access to the company's build and release infrastructure, allowing them to tamper with plugin packages before they were delivered to paying customers through the official Easy Digital Downloads (EDD) update system at account.shapedplugin.com. This represents one of the most dangerous classes of supply chain compromise—attackers didn't need to breach individual sites; instead, they poisoned the source at the vendor level.


The backdoored plugins were designed to remain hidden and operate with maximum privilege. When activated, they execute a loader on every WordPress admin page that silently contacts a remote command-and-control server (194.76.217.28:2871), downloads a malicious payload, and activates it as a concealed plugin. The malware then erases its tracks to complicate forensic analysis and incident response. What makes this attack particularly insidious is that victims were running software they believed to be legitimate updates from a trusted vendor.


The compromise affects three ShapedPlugin products: Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro. Critically, the free versions of these plugins distributed through WordPress.org remained unaffected—only the Pro builds delivered through ShapedPlugin's proprietary update infrastructure were weaponized. This distinction is important for site owners attempting to assess their exposure.


## Severity and Impact


| Attribute | Details |

|-----------|---------|

| CVE IDs | CVE-2026-49777 (Product Slider Pro); CVE-2026-10735 (overall incident) |

| CVSS Scores | 10.0 (Product Slider Pro) / 9.8 (overall) |

| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |

| Attack Vector | Network |

| Attack Complexity | Low |

| Privileges Required | None |

| User Interaction | None |

| CWE | CWE-426 (Untrusted Search Path), CWE-506 (Embedded Malicious Code) |


## Affected Products


  • Product Slider Pro for WooCommerce — versions before 3.5.4
  • Real Testimonials Pro — version 3.2.5
  • Smart Post Show Pro — versions before 4.0.2

  • *Note: Only Pro versions distributed through account.shapedplugin.com are affected. Free versions on WordPress.org are not compromised.*


    ## Capabilities of the Injected Malware


    Once the backdoor establishes itself, the hidden malicious plugin gains extensive control over the WordPress installation:


  • Credential Harvesting: Captures plaintext credentials and two-factor authentication (2FA) codes from all user accounts
  • Data Exfiltration: Automatically extracts and exfiltrates sensitive configuration data including database credentials, authentication keys, and debug settings from wp-config.php
  • Email Gateway Compromise: Captures SMTP credentials from WP Mail SMTP, Post SMTP, and Easy WP SMTP plugins
  • Transaction Data Theft: Harvests WooCommerce order data from the previous three months, including payment method breakdowns
  • Persistence Mechanisms: Establishes multiple backdoors including arbitrary file writes via custom REST endpoints when supplied the correct authentication token
  • Web Shell Deployment: Installs command-execution web shells for direct server access
  • Administrative Account Enumeration: Lists all administrator accounts and registration dates for further targeting
  • Self-Hiding: Hides itself from the WordPress plugin management interface to avoid detection

  • ## Mitigations


    Immediate Actions (24-48 hours):


    1. Update immediately — Install the patched versions of Product Slider Pro for WooCommerce (3.5.4+), Real Testimonials Pro (3.2.6+), and Smart Post Show Pro (4.0.2+) as soon as they become available following ShapedPlugin's security review.


    2. Reset all passwords — Force password resets for all WordPress user accounts, with particular urgency for administrator and editor accounts. The malware captures plaintext credentials.


    3. Revoke and regenerate 2FA secrets — Disable and reconfigure two-factor authentication for all users, as the backdoor specifically targets 2FA codes.


    4. Audit administrator accounts — Review the users list for unauthorized administrator accounts created during the compromise window. Check account creation dates against your known administrative team.


    Secondary Actions (1-2 weeks):


    5. Review mail plugin configurations — Examine SMTP settings in WP Mail SMTP, Post SMTP, and Easy WP SMTP for unauthorized modifications or credential theft. Regenerate SMTP credentials if you use these plugins.


    6. Inspect wp-config.php — Review your wp-config.php file for any suspicious modifications. Consider regenerating database credentials and authentication keys if you cannot rule out unauthorized access.


    7. Scan for persistent backdoors — Run a WordPress security scanner (Wordfence, Sucuri, iThemes Security) to detect any remaining malware, web shells, or hidden plugins left by the initial compromise.


    8. Review file system changes — Check for suspicious files, particularly web shells and the loader script. Look for the file "install-persistent.php" or unexpected .php files in plugin or theme directories.


    9. Check WooCommerce access logs — If you operate WooCommerce, audit order data access logs for unauthorized exports or modifications during the compromise period.


    10. Segment networks — For multi-site WordPress installations or managed hosting scenarios, implement network segmentation to limit the blast radius of future plugin compromises.


    ## References


  • Wordfence Security Analysis: https://www.wordfence.com/blog/2026/06/shapedplugin-supply-chain-attack
  • CVE-2026-49777: https://nvd.nist.gov/vuln/detail/CVE-2026-49777
  • CVE-2026-10735: https://nvd.nist.gov/vuln/detail/CVE-2026-10735
  • ShapedPlugin Official Notice: https://www.shapedplugin.com/security-advisory

  • ---


    ## HackWire Analysis


    This incident exemplifies why supply chain security remains one of the most stubborn problems in cybersecurity. ShapedPlugin's customers did everything "right"—they purchased legitimate licenses, installed updates through official channels, and trusted a vendor's build pipeline. Yet they became victims anyway because the vendor's infrastructure was compromised upstream.


    The attack reveals a troubling asymmetry: a single vulnerability in a vendor's release pipeline can simultaneously compromise thousands of sites in minutes, but detection and response require each individual site owner to understand they were targeted, recognize the malware's behavior, and take coordinated action. Many site owners may never notice the compromise until they experience unauthorized database access or discover a web shell months later.


    The malware's design shows sophistication beyond spray-and-pray commodity attacks. The fact that it deliberately hides itself, establishes multiple persistence mechanisms, and exfiltrates both secrets *and* operational data (order history, user accounts) suggests this wasn't a ransomware drop—it was reconnaissance. Attackers who compromise a WordPress installation at this level typically spend weeks extracting sensitive data before triggering obvious malicious behavior. Site owners should assume that any database credentials, API keys, or customer payment data has been compromised and act accordingly.


    The broader lesson: even small plugin vendors operate in supply chain positions that can cascade risk across entire industries. WordPress powers over 43% of websites. When a plugin vendor falls, thousands of e-commerce operations, service businesses, and publishers become collateral damage. The ecosystem needs improved code-signing, vendor security auditing, and faster distribution of security updates.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)