logo

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

ID: d5e50eee-e326-5ade-9ce9-058e943e4abe

STIX ID: report--d5e50eee-e326-5ade-9ce9-058e943e4abe

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-06-22

Date Updated: 2026-06-23

Author: [email protected] (The Hacker News)

...
...

A supply‑chain attack compromised ShapedPlugin's paid WordPress Pro plugins distributed via the vendor's Easy Digital Downloads infrastructure, injecting a loader that fetched and installed a hidden backdoor (contacting 194.76.217.28:2871), which created a fake plugin, exfiltrated wp-config and mail/WooCommerce data, captured credentials and 2FA codes, and provided remote code execution and persistence; CVEs were assigned and the vendor is reviewing distribution processes while recommending password and 2FA resets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.