ShapedPlugin Confirms Malware Distributed to Customers via Official Update System

WordPress plugin developer ShapedPlugin acknowledged in mid-June 2026 that its official update infrastructure had been compromised, resulting in a supply chain attack that distributed malware-infected versions of three of its paid plugins directly to customers. According to security researchers, the malicious code was first injected into the company’s software builds on May 21, allowing attackers to steal website credentials and sensitive e-commerce data for several weeks before the breach was contained.

The incident affected the “Pro” versions of three specific plugins: Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro. The free versions of ShapedPlugin’s products, which are hosted on the official WordPress.org repository and have a combined installation base of over 400,000 sites, were not affected by this attack, as the compromise was limited to the vendor’s private release infrastructure.

For any small or mid-sized business running an e-commerce operation, this type of incident is a direct threat to the bottom line, not merely a technical inconvenience. When a trusted software update delivers malware, it can lead to the theft of customer payment information, administrative credentials, and proprietary business data, triggering catastrophic financial losses and reputational damage. In our experience, business owners often underestimate the operational vulnerabilities inherent in their digital supply chain—the third-party tools and plugins that their websites rely on. The focus is usually on external threats, but an attack that comes from a trusted vendor is far more insidious and difficult to detect.

This is precisely why we integrate digital threats into our comprehensive financial risk management services. Protecting a company’s assets now means safeguarding the digital infrastructure that generates revenue and holds customer data. A single breach can lead to regulatory fines, legal liability, and a complete loss of customer trust that can take years to rebuild. At C&S Finance Group LLC, we help businesses identify and mitigate these modern operational risks before they become balance-sheet disasters. Business owners can learn more about building a resilient operational and financial strategy at csfinancegroup.com.

Security analysts at the WordPress security company Defiant, which operates the WordFence firewall, first began receiving reports from customers about potentially malicious updates on June 10. After downloading and analyzing the infected plugins directly from the ShapedPlugin website on June 12, the researchers confirmed the breach. ShapedPlugin publicly acknowledged the incident on June 16, stating its team had “immediately initiated an investigation” and “implemented the necessary measures to mitigate the issue.”

The attack was executed by compromising the vendor’s build pipeline, the system used to package and distribute its premium software. Attackers injected a malicious loader file named `LicenseLoader.php` into the plugins. When a site administrator logged into their WordPress dashboard, this loader would contact a remote command-and-control server to download a more sophisticated backdoor. This backdoor was cleverly disguised as a WooCommerce component and was engineered to be hidden from the website’s list of installed plugins, making it difficult for a non-technical user to discover.

Once installed, the malware was capable of stealing a wide array of sensitive information. According to security reports, this included WordPress administrator login credentials, two-factor authentication (2FA) secrets, database credentials, and SMTP email server credentials. For businesses using the affected WooCommerce plugin, the backdoor also targeted and exfiltrated recent customer order data, creating a significant data privacy risk.

The incident has been assigned the identifier CVE-2026-10735 and carries a critical CVSS severity score of 9.8 out of 10. This score reflects the fact that the vulnerability could be exploited remotely by an unauthenticated attacker, without any user interaction, to achieve a full takeover of an affected website.

ShapedPlugin has since released clean versions of the compromised software. Users are urged to update immediately to Product Slider Pro version 3.5.4, Real Testimonials Pro version 3.2.6, and Smart Post Show Pro version 4.0.2. The specific backdoored releases identified by researchers include Smart Post Show Pro 4.0.1, Product Slider for WooCommerce Pro 3.5.2, and Real Testimonials Pro 3.2.4.

This attack is part of a growing trend of supply chain compromises targeting popular software vendors. It follows a similar recent incident in which the update mechanism for the OptinMonster plugin was breached. By targeting the official update channel, attackers leverage the trust between a vendor and its customers to bypass standard security measures like firewalls, which are configured to allow traffic from known, legitimate sources.

Moving forward, this incident underscores the critical importance of vetting the security practices of third-party software providers. For businesses operating on platforms like WordPress, it serves as a reminder that vigilance is required even when installing updates from trusted developers. Website owners should monitor their systems for unusual activity, employ endpoint security solutions, and ensure they have a robust data backup and recovery plan in place.