On June 11, 2026, a supply chain compromise was detected affecting ShapedPlugin, a vendor with over 400,000 active installations. Attackers injected backdoor code into Pro plugin releases distributed through official channels, impacting users who followed security best practices. Fortunately, Wordfence customers are protected with malware signatures for the backdoor used in this attack.
What Happened?
The compromise was identified after a Wordfence customer reported suspicious activity. Attackers gained access to ShapedPlugin’s distribution pipeline, allowing them to insert malicious code into Pro versions of plugins, such as Product Slider Pro and Real Testimonials Pro. This attack is particularly concerning as it affects users who installed updates from the vendor’s official channels, believing they were secure.
What Are the Implications for Users?
Users of the affected Pro plugins face significant security risks, including unauthorized access to their sites. The backdoor allows attackers to execute commands and potentially steal sensitive information. It’s crucial for site owners to verify if they are using any compromised plugins and to take immediate action to secure their installations.
How to Protect Yourself?
Site owners should check for updates from ShapedPlugin and apply any security patches as they become available. Regularly review installed plugins to ensure they are up-to-date and monitor for any suspicious activity. Implementing a robust security solution, like Wordfence, can help detect and mitigate threats.
Frequently Asked Questions
What should I do if I use ShapedPlugin Pro plugins?
Immediately check for updates from ShapedPlugin and apply any security patches as they become available.
How can I tell if my site is affected by the ShapedPlugin compromise?
Review your installed plugins for any ShapedPlugin Pro versions and ensure they are updated to the latest secure releases.
What is a supply chain compromise?
A supply chain compromise occurs when attackers infiltrate a vendor’s distribution process to inject malicious code into legitimate software.