discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack, affecting Pro plugin builds distributed through the vendor's Easy Digital Downloads infrastructure. The compromised plugins incorporate a loader that fetches a payload from a remote se…

By Ravie Lakshmanan·Jun 22·thehackernews.com·2 min read

Intelligence analysis by Llama 3.3 70B

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Image: thehackernews.com

The supply chain attack compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases. The affected plugins include Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro.

Why it matters

This incident highlights the risks of supply chain attacks, which can compromise even legitimate software updates. It also underscores the importance of monitoring and securing the build and distribution pipeline to prevent such attacks.

Imagine you bought a legitimate software update, but it had a hidden backdoor that allowed hackers to access your site. That's what happened with some WordPress plugins. The hackers compromised the software update process, so even legitimate updates had malware. It's like finding a Trojan horse in a trusted package.

Analysis

Supply Chain Attack Vector

The attack on ShapedPlugin's WordPress Pro plugins is a prime example of a supply chain attack, where the attacker targets the vendor's build and distribution pipeline to inject malicious code into the software. This type of attack can be particularly devastating, as it can compromise even legitimate software updates and affect a large number of users.

The attackers managed to tamper with the official release channels and push backdoor code into the Pro plugin releases distributed through the vendor's Easy Digital Downloads infrastructure. The compromised plugins include Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro.

Malware Capabilities

The malware incorporated into the compromised plugins is capable of capturing credentials in plaintext and two-factor authentication (2FA) codes. It also establishes multiple persistence methods, enabling arbitrary file writes via a custom REST endpoint when provided a specific authentication token. Additionally, it can drop a web shell with command execution features, allowing the attackers to execute arbitrary commands on the compromised site.

Impact and Mitigation

The impact of this attack can be significant, as it exposes site owners who purchased legitimate licenses and installed updates directly from the vendor's official update system to malware. To mitigate the attack, site owners are recommended to reset all passwords, revoke and regenerate 2FA secrets for all users, review administrator accounts for unauthorized additions, and check mail plugin configurations for modified SMTP credentials.

Security Measures

To prevent such attacks in the future, it is essential to implement robust security measures, including monitoring and securing the build and distribution pipeline. This can include implementing code signing, using secure protocols for software updates, and conducting regular security audits and testing. Additionally, users should be cautious when installing software updates and should only install updates from trusted sources.

Key points

  • Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack
  • The affected plugins include Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro
  • The malware incorporated into the compromised plugins can capture credentials and establish persistence methods
The Upside

The incident highlights the importance of supply chain security, and the vendor's prompt response and efforts to review and secure their distribution and release processes are a positive step. Additionally, the incident raises awareness about the risks of supply chain attacks and the need for users to be vigilant when installing software updates.

The Downside

The attack on ShapedPlugin's WordPress Pro plugins is a concerning example of the risks of supply chain attacks. The fact that the attackers were able to compromise the vendor's build and distribution pipeline and push backdoor code into legitimate software updates is a significant concern. If left unchecked, such attacks can have devastating consequences for users and organizations.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritywordpresssupply-chain-attackmalware

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 22, 2026

Source

thehackernews.com

Share

Topics

securitywordpresssupply-chain-attackmalware

Related

More from this desk

Aug 20·bleepingcomputer.com

Microsoft says August Windows updates may cause gaming issues

Microsoft is investigating reports that its August 2026 Windows updates, specifically KB5121003, are causing some games to freeze, crash, or fail to launch on Windows 11 systems.

Aug 20·thehackernews.com

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

A critical flaw in the Elementor Pro WordPress plugin, CVE-2026-32475, allows unauthenticated attackers to upload dangerous PHP files and achieve remote code execution.

Aug 20·bleepingcomputer.com

OpenAI confirms ChatGPT is down as logins and signups fail

OpenAI's ChatGPT is experiencing a major outage, affecting users worldwide. Users are unable to sign in, create accounts, or load chats, including previous conversations.

Aug 19·bleepingcomputer.com

Rogue ransomware affiliate poses as recovery firm to steal payments

A suspected ransomware affiliate, operating as "Ransom Busters," is contacting victims before attacks become public, falsely claiming to be a recovery firm that can provide decryption keys and delete stolen data for a fee.