CVE-2026-49777
CVSS 10 CRITICAL: improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for… EPSS 2% (74th percentile).
Vulnerabilities & Exploits · Supply Chain
ShapedPlugin’s paid update channel became the attack path, so the normal act of staying current could hand attackers access instead of safety. The malicious build hides as a fake WooCommerce plugin, wakes up when an admin opens WordPress, steals passwords, 2FA secrets, and database keys, and can write files on the server before it deletes itself.
The infected releases were pushed through the vendor’s official update system for three paid plugins: Product Slider Pro for WooCommerce before 3.5.4, Real Testimonials Pro 3.2.5, and Smart Post Show Pro before 4.0.2. Wordfence said the backdoor was injected into ShapedPlugin’s Pro builds on May 21, with customer reports on June 10, infected copies confirmed on June 12, and the vendor acknowledging the incident on June 16.
This is the kind of compromise that survives the usual ‘check for unknown plugins’ response, because the payload installs itself under a hidden name and erases traces. The trust boundary that breaks here is the update channel itself, and that same problem can exist anywhere a vendor can push signed-looking software into customer systems.
2 sources · Jun 22
CVSS 10 CRITICAL: improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for… EPSS 2% (74th percentile).
The Hacker News
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Attackers backdoored ShapedPlugin Pro updates, stealing credentials, 2FA codes, wp-config.php data, and WooCommerce order details.
originalBleepingComputer
ShapedPlugin update flow hacked to infect WordPress sites
Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack that distributed infected releases to paying customers via the vendor's official update system.
originalPart of the PlainSec briefing for 2026-06-18
Every edition of this story: Trusted Plugin Updates Became the Payload