The compromise of ShapedPlugin’s premium WordPress plugin distribution system demonstrates the serious risks created by software supply-chain attacks.
Attackers inserted malicious code into legitimate Pro plugin updates delivered through the vendor’s official update channel. As a result, website owners could become infected even though they purchased licensed software and followed the normal update process.
Confirmed affected products include Real Testimonials Pro, Product Slider Pro for WooCommerce, and Smart Post Show Pro. Free versions distributed through the WordPress.org repository were not identified as affected.
The malicious updates installed a hidden plugin that provided several backdoor mechanisms. It could steal WordPress credentials, session cookies, database information, email-service credentials, WooCommerce order data, and two-factor authentication secrets. It also allowed attackers to bypass login controls, execute commands, modify files, and access the website database.
The theft of two-factor authentication secrets is particularly concerning because changing an administrator’s password may not be sufficient. Attackers possessing the TOTP seed could continue generating valid authentication codes.
Organizations that installed or updated any ShapedPlugin Pro product between April and June 2026 should treat the website as potentially compromised. Administrators should install verified clean releases, scan the complete site, check for hidden or unfamiliar plugins, review administrator accounts, and inspect files and database entries for unauthorized changes.
All WordPress administrator passwords, database credentials, API keys, email-service credentials, session cookies, and two-factor authentication secrets should be revoked or replaced. Simply removing the affected plugin may leave the attacker’s secondary backdoors intact.
The incident shows that trusted update channels can themselves become attack vectors. Software updates remain essential, but organizations must also verify package integrity, monitor unexpected code changes, maintain reliable backups, and watch for abnormal behaviour after updates.
The key lesson is uncomfortable but simple: legitimate software obtained from an official vendor can still become malicious when the vendor’s build or distribution process is compromised. Trusting the source is no longer enough; the delivered code must also be continuously verified.

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels," Wordfence said in an analysis
Source: ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack via The Hacker News — published 22 Jun 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.