FeedApplication SecurityShapedPlugin update flow hacked to infect WordPress sites...
Application SecurityBleeping Computer
9.8CRITICAL

ShapedPlugin update flow hacked to infect WordPress sites

📅 18 June 2026 at 12:55 UTC📰 Bleeping ComputerView original source ↗
ShapedPlugin update flow hacked to infect WordPress sites

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

ShapedPlugin's Pro builds were compromised in a supply chain attack, resulting in the distribution of infected WordPress plugins that steal credentials and grant remote file-writing capabilities.

⚙️Technical Details
💥Impact Assessment
Severity: Critical
🛡️Recommended Actions
1Reset all passwords on affected sites
2Regenerate two-factor authentication (2FA) secrets
3Review user lists for rogue additions
📦Affected Products
Product Slider Pro:before 3.5.4Real Testimonials Pro:3.2.5Smart Post Show Pro:before 4.0.2

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed