supply-chain
ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
Critical
Summary
A supply chain attack compromised multiple WordPress plugins from ShapedPlugin, injecting backdoor code into Pro plugin releases distributed through official update channels. The malicious plugins, affecting versions of Product Slider Pro, Real Testimonials Pro, and Smart Post Show Pro, were designed to steal sensitive data and establish persistence on compromised websites. This incident highlights the risks associated with relying on third-party plugins and underscores the importance of diligent security practices.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
