FeedMalwareSupply-chain attack injects backdoor on ShapedPlugin WordPre...
MalwareCyber Insider
10.0CRITICAL

Supply-chain attack injects backdoor on ShapedPlugin WordPress software

📅 17 June 2026 at 15:22 UTC📰 Cyber InsiderView original source ↗
Supply-chain attack injects backdoor on ShapedPlugin WordPress software

A supply-chain attack targeted ShapedPlugin, a WordPress plugin developer with more than 400,000 active installations across its free products. The backdoored premium plugin releases were distributed through the company's official update infrastructure. The malware provided attackers with persistent access to websites, stole administrator credentials and two-factor authentication (2FA) secrets, and deployed multiple remote access mechanisms. … The post Supply-chain attack injects backdoor on ShapedPlugin WordPress software appeared first on CyberInsider.

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A supply-chain attack compromised ShapedPlugin's premium plugin products, injecting a backdoor that provided attackers with persistent access and stole administrator credentials and 2FA secrets.

⚙️Technical Details
Affected Systems
ShapedPlugin premium plugins
Attack Vectors
build pipeline compromise
💥Impact Assessment
Severity: critical
Who Is at Risk
Administrators who installed ShapedPlugin premium plugins between April and June 2026
🛡️Recommended Actions
1Scan for malware and remove unauthorized accounts
2Rotate WordPress, database, SMTP, and API credentials
3Regenerate all two-factor authentication secrets
📦Affected Products
Product Slider Pro for WooCommerce
🔐NVD Verified DataVERIFIED
CVE-2026-49777CVSS 10CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-1284

Read the full article

This is a curated summary. The complete article is available at Cyber Insider.

Read on Cyber Insider
← Back to feed