logo

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

ID: 7db3a3b7-9e00-564c-8f84-bbf5b8bd6661

STIX ID: report--7db3a3b7-9e00-564c-8f84-bbf5b8bd6661

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-06-22

Date Updated: 2026-06-24

...
...

Multiple premium WordPress plugins from ShapedPlugin were backdoored after attackers compromised the vendor's build and distribution pipeline, causing Pro releases distributed outside WordPress.org to include malicious code that can enable remote code execution, credential theft, and unauthorized site access; site operators are advised to audit versions, disable affected plugins, scan for indicators of compromise, review logs, rotate credentials, and monitor vendor communications for verified clean releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.