supply-chain
ShapedPlugin update flow hacked to infect WordPress sites
High
Summary
A supply-chain attack targeting WordPress plugins from ShapedPlugin resulted in malicious updates containing a backdoor designed to steal sensitive data from affected websites. The attack exploited a compromised build pipeline, impacting three paid plugins and highlighting vulnerabilities within vendor update systems. Affected sites are advised to immediately reset passwords and regenerate 2FA secrets.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data