ShapedPlugin WordPress Pro Plugins Backdoored via Build-Pipeline Supply Chain Compromise (CVE-2026-49777, CVE-2026-10735)
ShapedPlugin WordPress Pro Plugins Backdoored via (TL-2026-0908), also tracked as ShapedPlugin Supply Chain Attack, is a critical-severity supply-chain compromise scored CVSS 10, first published 2026-06-22. It has no confirmed attribution, affects ShapedPlugin, LLC Product Slider Pro for WooCommerce, references 2 CVEs (CVE-2026-49777, CVE-2026-10735), maps to 22 MITRE ATT&CK techniques (T1005, T1036, T1041), and is covered by 9 detection rules and 18 indicators of compromise.
Key facts for TL-2026-0908
- Threat ID
- TL-2026-0908
- Also known as
- ShapedPlugin Supply Chain Attack, ShapedPlugin Build Pipeline Breach
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-06-22
- Last reviewed
- 2026-06-22
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- e-commerce, retail, small business, web hosting, publishing
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
Malware and tooling in ShapedPlugin WordPress Pro Plugins Backdoored via
Malware and tooling: woocommerce-subscription (fake plugin), Adminer 5.2.1, Custom PHP multi-stage backdoor (loader + fake plugin web shell), Tiny File Manager 2.6
Threat actors breached ShapedPlugin's licensed update/distribution pipeline (account.shapedplugin.com on Easy Digital Downloads) during a roughly two-hour window on 21 May 2026 and trojanized Pro builds of Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro. A LicenseLoader.php stager fires on every admin page load, fetches a second-stage payload, installs it as a hidden fake plugin (woocommerce-subscription / woocommerce-notification), and steals credentials, 2FA secrets, database/SMTP credentials, and WooCommerce payment data. Active exploitation is confirmed across an installation base exceeding 400,000 sites; free WordPress.org versions were unaffected.
How ShapedPlugin WordPress Pro Plugins Backdoored via works
Between approximately April and June 2026, attackers compromised the build and distribution pipeline of ShapedPlugin, LLC and injected malicious code into the Pro (paid) releases of multiple widely deployed WordPress plugins. The tampered packages were served through the vendor's official licensed-update channel at account.shapedplugin.com, which runs on Easy Digital Downloads, meaning paying customers received the backdoor through the same trusted mechanism used for legitimate updates. Wordfence telemetry indicates the malicious code was introduced during a narrow two-hour build-pipeline modification window on or about 21 May 2026.
The compromised plugin packages embed a loader, LicenseLoader.php, that executes on every WordPress administrator page load. On first admin access the loader contacts a remote command-and-control server (194.76.217.28 on TCP port 2871), retrieves a second-stage backdoor payload, writes it into wp-content/plugins as a counterfeit plugin (observed slugs woocommerce-subscription and woocommerce-notification), and activates it. The fake plugin hides itself from the WordPress admin plugin list, and the LicenseLoader.php stager self-deletes after installation to erase forensic evidence.
The second-stage backdoor is a multi-capability implant. It hooks WordPress login flows to capture administrator credentials in plaintext (usernames, passwords, active session cookies, user roles, source IP addresses and browser fingerprints) and intercepts two-factor authentication codes/secrets, targeting common 2FA plugins including WP 2FA, Wordfence Login Security, Really Simple SSL 2FA, and the Two-Factor plugin, exfiltrating TOTP secrets to generate.2faplugin.org. It registers custom REST API endpoints that allow arbitrary file writes and command execution (a web shell), and it bundles attacker tooling — Tiny File Manager 2.6 and Adminer 5.2.1 — for hands-on-keyboard file and database access. A persistence/exfiltration script (install-persistent.php) extracts wp-config.php contents (database credentials and WordPress auth/secret keys), enumerates administrator accounts with their registration dates, harvests mail-plugin credentials (WP Mail SMTP, Post SMTP, Easy WP SMTP), and exfiltrates WooCommerce order/payment records from the preceding three months.
The Product Slider Pro for WooCommerce compromise was assigned CVE-2026-49777 (CVSS 10.0); the broader multi-plugin incident is tracked as CVE-2026-10735 (CVSS 9.8). Affected releases include Product Slider for WooCommerce Pro before 3.5.4 (malicious build 3.5.2 observed), Real Testimonials Pro 3.2.5 (malicious build 3.2.4 observed), and Smart Post Show Pro before 4.0.2 (malicious build 4.0.1 observed). ShapedPlugin acknowledged the incident on 16 June 2026 and shipped clean releases: Product Slider Pro 3.5.4, Real Testimonials Pro 3.2.6, and Smart Post Show Pro 4.0.2.
MITRE ATT&CK techniques used in TL-2026-0908
Collection
Defense Evasion
T1036 Masquerading; T1070 Indicator Removal; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Credential Access
T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer
Discovery
T1087 Account Discovery; T1518 Software Discovery
Persistence
T1136 Create Account; T1505 Server Software Component; T1554 Compromise Host Software Binary
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship
Resource Development
T1584 Compromise Infrastructure
Impact
Affected products and versions in ShapedPlugin WordPress Pro Plugins Backdoored via
- ShapedPlugin, LLC — Product Slider Pro for WooCommerce
Vulnerable versions: < 3.5.4; 3.5.2
Fixed in: 3.5.4 - ShapedPlugin, LLC — Real Testimonials Pro
Vulnerable versions: 3.2.5; 3.2.4
Fixed in: 3.2.6 - ShapedPlugin, LLC — Smart Post Show Pro
Vulnerable versions: < 4.0.2; 4.0.1
Fixed in: 4.0.2
Remediation for ShapedPlugin WordPress Pro Plugins Backdoored via
Patches
- Product Slider Pro for WooCommerce 3.5.4
- Real Testimonials Pro 3.2.6
- Smart Post Show Pro 4.0.2
Immediate actions
- Identify and update Product Slider Pro for WooCommerce to 3.5.4+, Real Testimonials Pro to 3.2.6+, and Smart Post Show Pro to 4.0.2+
- Hunt for and remove LicenseLoader.php, install-persistent.php, and the fake plugin directories wp-content/plugins/woocommerce-subscription and wp-content/plugins/woocommerce-notification
- Block outbound traffic to 194.76.217.28 (TCP/2871) and to generate.2faplugin.org at the perimeter/DNS
- Treat all administrator credentials, session cookies, and 2FA secrets as compromised: force password resets and re-enroll MFA
- Rotate wp-config.php database credentials and all WordPress auth/secret keys and salts
- Rotate SMTP/mail-service credentials for WP Mail SMTP, Post SMTP, and Easy WP SMTP
Workarounds
- Temporarily deactivate and remove affected ShapedPlugin Pro plugins until clean versions are validated
- Audit and remove unrecognized administrator accounts created since 21 May 2026
Longer-term hardening
- Deploy file-integrity monitoring on wp-content/plugins and wp-config.php
- Restrict and monitor custom REST API route registration and arbitrary file writes
- Verify plugin update integrity (signatures/checksums) before deployment
- Deploy a WAF/endpoint solution with behavioral detection for web shells and credential capture
CVEs associated with ShapedPlugin WordPress Pro Plugins Backdoored via
Weaknesses (CWE) in ShapedPlugin WordPress Pro Plugins Backdoored via
CWE-1284, CWE-506, CWE-94
Timeline of ShapedPlugin WordPress Pro Plugins Backdoored via
- Attackers modified the ShapedPlugin build/distribution pipeline during an approximately two-hour window and injected backdoor code into Pro plugin builds.
- WPScan / CVE process publishes initial vulnerability records for the affected ShapedPlugin Pro plugins.
- CVE-2026-49777 (CVSS 10.0) published in NVD for Product Slider Pro for WooCommerce — 'Malicious Software Implanted'.
- First customer reports of malicious updates delivered through the licensed update channel.
- Wordfence Threat Intelligence confirms the breach via firewall/telemetry analysis.
- Malicious plugin builds observed still being distributed as recently as this date.
- ShapedPlugin acknowledges the incident and announces clean, patched releases pending validation.
- CVE-2026-49777 record last modified in NVD.
- Public reporting (The Hacker News and others) details the supply-chain backdoor, IOCs, and patched versions.
Sources cited for ShapedPlugin WordPress Pro Plugins Backdoored via
- ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
- ShapedPlugin update flow hacked to infect WordPress sites
- ShapedPlugin Supply Chain Attack: WordPress Pro Plugins Backdoored
- Supply-chain attack injects backdoor on ShapedPlugin WordPress software
- ShapedPlugin Build Pipeline Breach Delivers Credential-Stealing Backdoor to 400,000+ WordPress Sites
- NVD - CVE-2026-49777
- Supply Chain Attack Compromises Multiple ShapedPlugin WordPress Plugins
- Backdoored ShapedPlugin Pro Updates Exposed WordPress Sites to Full Takeover
- Wordfence Threat Intelligence
Threats related to ShapedPlugin WordPress Pro Plugins Backdoored via
Detection coverage for TL-2026-0908
As of 2026-06-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0908 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.