logo

ShapedPlugin update flow hacked to infect WordPress sites

ID: de569762-0406-5c34-929a-5b94c20e605f

STIX ID: report--de569762-0406-5c34-929a-5b94c20e605f

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Bill Toulas

...
...

Multiple paid ShapedPlugin WordPress plugins were compromised via the vendor's build/release pipeline, delivering a malicious loader (LicenseLoader.php) that fetched and installed a hidden fake WooCommerce plugin backdoor. The malware exfiltrates WordPress credentials, 2FA secrets, wp-config database/auth keys, SMTP credentials, admin details and recent WooCommerce orders; Wordfence observed infected builds in late May/early June and the vendor published patched releases and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.