logo

ShapedPlugin Supply Chain Attack Exposes WordPress Sites

ID: 6e758ed3-5ebd-5d4f-8d2c-b24658920858

STIX ID: report--6e758ed3-5ebd-5d4f-8d2c-b24658920858

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Do Son

...
...

Security researchers reported a June 11, 2026 supply-chain compromise of premium WordPress plugins where attackers injected a malicious LicenseLoader.php into builds distributed via Easy Digital Downloads; the loader downloads a payload that installs a fake woocommerce-subscription plugin, creates persistent backdoors (custom REST endpoint, admin tools, hardcoded bypass), and exfiltrates credentials and TOTP 2FA seeds to generate.2faplugin.org — affecting specific premium plugin versions (e.g., Real Testimonials Pro 3.2.5) while leaving free repository versions untouched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.