ShapedPlugin WordPress Pro Plugins Backdoored via Build-Pipeline Supply Chain Compromise (CVE-2026-49777, CVE-2026-10735)

ShapedPlugin WordPress Pro Plugins Backdoored via (TL-2026-0908), also tracked as ShapedPlugin Supply Chain Attack, is a critical-severity supply-chain compromise scored CVSS 10, first published 2026-06-22. It has no confirmed attribution, affects ShapedPlugin, LLC Product Slider Pro for WooCommerce, references 2 CVEs (CVE-2026-49777, CVE-2026-10735), maps to 22 MITRE ATT&CK techniques (T1005, T1036, T1041), and is covered by 9 detection rules and 18 indicators of compromise.

Key facts for TL-2026-0908

Threat ID
TL-2026-0908
Also known as
ShapedPlugin Supply Chain Attack, ShapedPlugin Build Pipeline Breach
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
2026-06-22
Last reviewed
2026-06-22
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
e-commerce, retail, small business, web hosting, publishing
Target regions
Global
Detection rules
9
Indicators of compromise
18

Malware and tooling in ShapedPlugin WordPress Pro Plugins Backdoored via

Malware and tooling: woocommerce-subscription (fake plugin), Adminer 5.2.1, Custom PHP multi-stage backdoor (loader + fake plugin web shell), Tiny File Manager 2.6

Threat actors breached ShapedPlugin's licensed update/distribution pipeline (account.shapedplugin.com on Easy Digital Downloads) during a roughly two-hour window on 21 May 2026 and trojanized Pro builds of Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro. A LicenseLoader.php stager fires on every admin page load, fetches a second-stage payload, installs it as a hidden fake plugin (woocommerce-subscription / woocommerce-notification), and steals credentials, 2FA secrets, database/SMTP credentials, and WooCommerce payment data. Active exploitation is confirmed across an installation base exceeding 400,000 sites; free WordPress.org versions were unaffected.

How ShapedPlugin WordPress Pro Plugins Backdoored via works

Between approximately April and June 2026, attackers compromised the build and distribution pipeline of ShapedPlugin, LLC and injected malicious code into the Pro (paid) releases of multiple widely deployed WordPress plugins. The tampered packages were served through the vendor's official licensed-update channel at account.shapedplugin.com, which runs on Easy Digital Downloads, meaning paying customers received the backdoor through the same trusted mechanism used for legitimate updates. Wordfence telemetry indicates the malicious code was introduced during a narrow two-hour build-pipeline modification window on or about 21 May 2026.

The compromised plugin packages embed a loader, LicenseLoader.php, that executes on every WordPress administrator page load. On first admin access the loader contacts a remote command-and-control server (194.76.217.28 on TCP port 2871), retrieves a second-stage backdoor payload, writes it into wp-content/plugins as a counterfeit plugin (observed slugs woocommerce-subscription and woocommerce-notification), and activates it. The fake plugin hides itself from the WordPress admin plugin list, and the LicenseLoader.php stager self-deletes after installation to erase forensic evidence.

The second-stage backdoor is a multi-capability implant. It hooks WordPress login flows to capture administrator credentials in plaintext (usernames, passwords, active session cookies, user roles, source IP addresses and browser fingerprints) and intercepts two-factor authentication codes/secrets, targeting common 2FA plugins including WP 2FA, Wordfence Login Security, Really Simple SSL 2FA, and the Two-Factor plugin, exfiltrating TOTP secrets to generate.2faplugin.org. It registers custom REST API endpoints that allow arbitrary file writes and command execution (a web shell), and it bundles attacker tooling — Tiny File Manager 2.6 and Adminer 5.2.1 — for hands-on-keyboard file and database access. A persistence/exfiltration script (install-persistent.php) extracts wp-config.php contents (database credentials and WordPress auth/secret keys), enumerates administrator accounts with their registration dates, harvests mail-plugin credentials (WP Mail SMTP, Post SMTP, Easy WP SMTP), and exfiltrates WooCommerce order/payment records from the preceding three months.

The Product Slider Pro for WooCommerce compromise was assigned CVE-2026-49777 (CVSS 10.0); the broader multi-plugin incident is tracked as CVE-2026-10735 (CVSS 9.8). Affected releases include Product Slider for WooCommerce Pro before 3.5.4 (malicious build 3.5.2 observed), Real Testimonials Pro 3.2.5 (malicious build 3.2.4 observed), and Smart Post Show Pro before 4.0.2 (malicious build 4.0.1 observed). ShapedPlugin acknowledged the incident on 16 June 2026 and shipped clean releases: Product Slider Pro 3.5.4, Real Testimonials Pro 3.2.6, and Smart Post Show Pro 4.0.2.

MITRE ATT&CK techniques used in TL-2026-0908

Collection

T1005 Data from Local System

Defense Evasion

T1036 Masquerading; T1070 Indicator Removal; T1564 Hide Artifacts

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Credential Access

T1056 Input Capture; T1111 Multi-Factor Authentication Interception; T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

Discovery

T1087 Account Discovery; T1518 Software Discovery

Persistence

T1136 Create Account; T1505 Server Software Component; T1554 Compromise Host Software Binary

Initial Access

T1195 Supply Chain Compromise; T1199 Trusted Relationship

Resource Development

T1584 Compromise Infrastructure

Impact

T1657 Financial Theft

Affected products and versions in ShapedPlugin WordPress Pro Plugins Backdoored via

  • ShapedPlugin, LLC — Product Slider Pro for WooCommerce
    Vulnerable versions: < 3.5.4; 3.5.2
    Fixed in: 3.5.4
  • ShapedPlugin, LLC — Real Testimonials Pro
    Vulnerable versions: 3.2.5; 3.2.4
    Fixed in: 3.2.6
  • ShapedPlugin, LLC — Smart Post Show Pro
    Vulnerable versions: < 4.0.2; 4.0.1
    Fixed in: 4.0.2

Remediation for ShapedPlugin WordPress Pro Plugins Backdoored via

Patches

  • Product Slider Pro for WooCommerce 3.5.4
  • Real Testimonials Pro 3.2.6
  • Smart Post Show Pro 4.0.2

Immediate actions

  • Identify and update Product Slider Pro for WooCommerce to 3.5.4+, Real Testimonials Pro to 3.2.6+, and Smart Post Show Pro to 4.0.2+
  • Hunt for and remove LicenseLoader.php, install-persistent.php, and the fake plugin directories wp-content/plugins/woocommerce-subscription and wp-content/plugins/woocommerce-notification
  • Block outbound traffic to 194.76.217.28 (TCP/2871) and to generate.2faplugin.org at the perimeter/DNS
  • Treat all administrator credentials, session cookies, and 2FA secrets as compromised: force password resets and re-enroll MFA
  • Rotate wp-config.php database credentials and all WordPress auth/secret keys and salts
  • Rotate SMTP/mail-service credentials for WP Mail SMTP, Post SMTP, and Easy WP SMTP

Workarounds

  • Temporarily deactivate and remove affected ShapedPlugin Pro plugins until clean versions are validated
  • Audit and remove unrecognized administrator accounts created since 21 May 2026

Longer-term hardening

  • Deploy file-integrity monitoring on wp-content/plugins and wp-config.php
  • Restrict and monitor custom REST API route registration and arbitrary file writes
  • Verify plugin update integrity (signatures/checksums) before deployment
  • Deploy a WAF/endpoint solution with behavioral detection for web shells and credential capture

CVEs associated with ShapedPlugin WordPress Pro Plugins Backdoored via

CVE-2026-49777, CVE-2026-10735

Weaknesses (CWE) in ShapedPlugin WordPress Pro Plugins Backdoored via

CWE-1284, CWE-506, CWE-94

Timeline of ShapedPlugin WordPress Pro Plugins Backdoored via

  • Attackers modified the ShapedPlugin build/distribution pipeline during an approximately two-hour window and injected backdoor code into Pro plugin builds.
  • WPScan / CVE process publishes initial vulnerability records for the affected ShapedPlugin Pro plugins.
  • CVE-2026-49777 (CVSS 10.0) published in NVD for Product Slider Pro for WooCommerce — 'Malicious Software Implanted'.
  • First customer reports of malicious updates delivered through the licensed update channel.
  • Wordfence Threat Intelligence confirms the breach via firewall/telemetry analysis.
  • Malicious plugin builds observed still being distributed as recently as this date.
  • ShapedPlugin acknowledges the incident and announces clean, patched releases pending validation.
  • CVE-2026-49777 record last modified in NVD.
  • Public reporting (The Hacker News and others) details the supply-chain backdoor, IOCs, and patched versions.

Sources cited for ShapedPlugin WordPress Pro Plugins Backdoored via

Threats related to ShapedPlugin WordPress Pro Plugins Backdoored via

Detection coverage for TL-2026-0908

As of 2026-06-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0908 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats