ShapedPlugin Supply Chain Attack Exposes WordPress Sites
ID: 6e758ed3-5ebd-5d4f-8d2c-b24658920858
STIX ID: report--6e758ed3-5ebd-5d4f-8d2c-b24658920858
Feed Name: securityonline.info
Security researchers reported a June 11, 2026 supply-chain compromise of premium WordPress plugins where attackers injected a malicious LicenseLoader.php into builds distributed via Easy Digital Downloads; the loader downloads a payload that installs a fake woocommerce-subscription plugin, creates persistent backdoors (custom REST endpoint, admin tools, hardcoded bypass), and exfiltrates credentials and TOTP 2FA seeds to generate.2faplugin.org — affecting specific premium plugin versions (e.g., Real Testimonials Pro 3.2.5) while leaving free repository versions untouched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
