ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code.

“Attackers compromised the vendor’s build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels,” Wordfence said in an analysis

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

The Jqwik Anti-AI Affair

The Jqwik Anti-AI Affair Source: Hacker News

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability

BYOC Is Not Just ‘Deploy into Their Cloud’

BYOC Is Not Just ‘Deploy into Their Cloud’ Source: Hacker News