Wordfence Says ShapedPlugin Pro Updates Carried Backdoors
Wordfence says ShapedPlugin Pro plugin updates were distributed with backdoor code through official licensed channels.
Wordfence says a ShapedPlugin supply-chain compromise put backdoored Pro plugin packages into the vendor’s official update path, turning a normal update workflow into a WordPress security incident.
Table Of Content
- What Wordfence says happened
- Why this is worse than a normal plugin bug
- What WordPress site owners should do now
- Prioritize Pro installations, not just free plugin slugs
- Check for post-update compromise indicators
- Wait for verified vendor builds before restoring trust
- The bigger lesson for WordPress operations
The Wordfence Threat Intelligence Team reported on June 16, 2026 that it was notified on June 11 of a potential compromise affecting ShapedPlugin, a WordPress plugin vendor that Wordfence describes as having more than 400,000 active free plugin installations. The issue is fresh, high impact, and unusually uncomfortable for site owners because the suspect packages were not random downloads from a lookalike site. Wordfence says attackers compromised the vendor’s build and distribution pipeline and injected backdoor code into Pro plugin releases distributed through official licensed update channels.
That detail changes the risk model. A customer who bought a legitimate license, signed in to the vendor’s normal account system, and applied an available Pro update may have followed the expected maintenance path while still receiving malicious code.
What Wordfence says happened
Wordfence’s advisory identifies the issue as Multiple ShapedPlugin Plugins < various versions: Backdoored Software, assigns it CVE-2026-10735, and rates it 9.8 critical. The affected software named in the advisory is Product Slider Pro for WooCommerce, Real Testimonials Pro, and Smart Post Show Pro. Wordfence also notes that CVE-2026-49777 is a duplicate of the same issue.
The advisory says the compromise is limited to Pro plugin builds distributed through ShapedPlugin’s Easy Digital Downloads infrastructure at account.shapedplugin.com, not to the free plugins hosted in the WordPress.org plugin repository. That boundary matters: a site running only the free WordPress.org package is not in the same distribution path as a site pulling a commercial Pro ZIP or licensed update from the vendor.
Wordfence says it obtained a backdoored copy of Real Testimonials Pro 3.2.5 directly from the official vendor update endpoint on June 12. Its malware analysis describes a malicious LicenseLoader.php file and a modified plugin loader that runs on WordPress admin pages. Once triggered, the loader downloads a payload from a command-and-control server, installs it as a fake plugin under wp-content/plugins/woocommerce-subscription/, reports the victim domain back to the server, and then removes evidence of the initial loader path.
Why this is worse than a normal plugin bug
Most WordPress vulnerability triage starts with a familiar question: “Which version is installed, and is a patch available?” Supply-chain compromises force a harder question: “Can the update channel itself still be trusted?” In this case, Wordfence’s embedded vulnerability record lists a patched status, while the same report quotes ShapedPlugin as saying it had initiated an investigation, taken mitigation steps, and was preparing updated releases and validation tests. Site owners should therefore treat this as a live incident-response workflow rather than a simple one-click update story.
ShapedPlugin has a broad footprint. The WordPress.org profile for ShapedPlugin LLC lists the company as a plugin developer with a portfolio of WordPress plugins, and the WordPress.org plugin directory search shows public plugins such as Easy Accordion, WP Carousel, Smart Post, Real Testimonials, and Product Slider for WooCommerce with active-install counts attached to the free listings. The vendor’s own homepage describes a commercial WordPress and WooCommerce plugin portfolio and says its products empower more than 360,050 businesses and organizations worldwide.
What WordPress site owners should do now
Prioritize Pro installations, not just free plugin slugs
The first priority is inventory. Administrators should identify whether any site is running the Pro editions named by Wordfence: Product Slider Pro for WooCommerce, Real Testimonials Pro, or Smart Post Show Pro. The free WordPress.org listings are useful for understanding vendor footprint, but Wordfence’s report says the compromise centered on commercial Pro builds distributed through the vendor’s licensed infrastructure.
Check for post-update compromise indicators
Sites that installed or updated affected Pro packages around the incident window should be reviewed as potentially exposed. Wordfence’s report names a malicious loader, a modified plugin file, a command-and-control endpoint, and a fake plugin directory using the singular name woocommerce-subscription. Administrators should validate installed plugin directories, recently modified PHP files, unexpected admin users, outbound requests, and security scanner results rather than relying only on the WordPress plugins screen.
Wait for verified vendor builds before restoring trust
For affected sites, the safest operational stance is to pause automatic trust in the vendor update channel until ShapedPlugin and independent security sources confirm clean replacement builds. That does not mean every ShapedPlugin free user is affected; it means teams that used the commercial update path need stronger evidence before assuming a new package is safe. In practice, that means preserving copies of suspect ZIP files and logs for investigation, applying verified replacements only from confirmed channels, and running a malware scan after cleanup.
The bigger lesson for WordPress operations
This incident is another reminder that plugin security is not only about known CVEs. For commercial WordPress plugins, the release pipeline, license server, account portal, and updater code all become part of the trusted computing base. If an attacker can put a malicious build into a legitimate update channel, ordinary patch discipline can become the infection path.
Teams managing fleets of WordPress sites should keep a separate inventory of commercial plugins, update endpoints, vendor accounts, and deployment timestamps. They should also keep backups and file integrity baselines that make it possible to compare plugin contents before and after a vendor update. Those controls are less exciting than a new feature release, but they are what let responders answer the question that matters during a supply-chain event: what changed, where, and when?
Image credit: Cybersecurity.png by jaydeep_ / Pixabay, released under CC0 and resized to WebP for sxz.io.








No Comment! Be the first one.