logo

ShapedPlugin Update Flow Hacked to Infect WordPress Sites

ID: ea2e3585-5a4f-523c-bf3a-2335bc091793

STIX ID: report--ea2e3585-5a4f-523c-bf3a-2335bc091793

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

...
...

A supply-chain attack compromised ShapedPlugin's proprietary update infrastructure to distribute trojanized premium WordPress plugin updates to paying customers; malicious updates were staged as legitimate releases, delivered via the vendor's official update channel, and executed on sites after installation. The report highlights the heightened risk in premium plugin ecosystems due to automatic updates and lack of central repository integrity checks, recommends immediate auditing of recent updates, file integrity scans, log review, disabling automatic updates for third-party commercial plugins, and staging updates before production deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.