ShapedPlugin Supply Chain Attack Backdoors Pro Plugin Updates

Attackers backdoored ShapedPlugin Pro updates, deploying malware that steals credentials, 2FA secrets, and grants full site access.

Security Affairs

WordPress Plugins Backdoored in ShapedPlugin Supply Chain Attack

A recent supply chain attack on ShapedPlugin compromised the updates for several WordPress plugins, including Product Slider Pro for WooCommerce, injecting backdoor code that could give attackers full control of affected sites. This severe vulnerability, rated 10.0 on the CVSS scale, highlights the importance of staying vigilant about plugin…

https://osintsights.com/wordpress-plugins-backdoored-in-shapedplugin-supply-chain-attack?utm_source=mastodon&utm_medium=social

#SupplyChain #Wordpress #Shapedplugin #Cve202649777 #Backdoor

WordPress Plugins Backdoored in ShapedPlugin Supply Chain Attack

Learn about the ShapedPlugin supply chain attack that backdoored WordPress plugins and how to protect your site from similar threats now.

OSINTSights
ShapedPlugin update flow hacked to infect WordPress sites

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system.

BleepingComputer

CVE Alert: CVE-2026-3017 - shapedplugin - Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts - https://www.redpacketsecurity.com/cve-alert-cve-2026-3017-shapedplugin-smart-post-show-post-grid-post-carousel-slider-and-list-category-posts/

#OSINT #ThreatIntel #CyberSecurity #cve-2026-3017 #shapedplugin #smart-post-show-post-grid-post-carousel-and-slider-and-list-category-posts

CVE Alert: CVE-2026-3017 - shapedplugin - Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts - RedPacket Security

The Smart Post Show – Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all

RedPacket Security