news.mlab.sh
Back to the feed
supply-chain

ShapedPlugin update flow hacked to infect WordPress sites

High
Summary

A supply-chain attack targeting WordPress plugins from ShapedPlugin resulted in malicious updates containing a backdoor designed to steal sensitive data from affected websites. The attack exploited a compromised build pipeline, impacting three paid plugins and highlighting vulnerabilities within vendor update systems. Affected sites are advised to immediately reset passwords and regenerate 2FA secrets.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.