Application SecurityBleeping Computer
9.8 — CRITICAL
ShapedPlugin update flow hacked to infect WordPress sites
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
ShapedPlugin's Pro builds were compromised in a supply chain attack, resulting in the distribution of infected WordPress plugins that steal credentials and grant remote file-writing capabilities.
⚙️Technical Details
💥Impact Assessment
Severity: Critical
🛡️Recommended Actions
1Reset all passwords on affected sites
2Regenerate two-factor authentication (2FA) secrets
3Review user lists for rogue additions
📦Affected Products
Product Slider Pro:before 3.5.4Real Testimonials Pro:3.2.5Smart Post Show Pro:before 4.0.2
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
