Junglewise Threat Intelligence

CVE-2026-10735: ShapedPlugin Multiple WordPress Plugins supply chain backdoor

CVE-2026-10735 · Severity: info · CVSS 9.8 · Published 2026-06-24

Executive brief

Several premium WordPress plugins from ShapedPlugin were distributed with malicious code after the vendor's update server was compromised. This backdoor allows attackers to take full control of affected websites, steal login credentials, and exfiltrate sensitive data. Site owners using these plugins should update to the latest versions immediately to remove the malicious code.

Technical details

A supply chain attack resulted in the distribution of backdoored versions of Smart Post Show Pro (4.0.1), Product Slider for WooCommerce Pro (3.5.2), and Real Testimonials Pro (3.2.4). The malicious code, located in components such as 'includes/class-smart-show-pro-installer.php', allows unauthenticated remote attackers to deploy a second-stage payload from a hardcoded C2 server (194.76.217.28). This payload can exfiltrate credentials and establish persistence via a fake 'woocommerce-subscription' plugin. The vendor has released clean versions (4.0.2, 3.5.3, and 3.2.5 respectively) to mitigate the threat.

Affected products

  • ShapedPlugin Smart Post Show Pro < 4.0.2
  • ShapedPlugin Real Testimonials Pro < 3.2.5
  • ShapedPlugin Product Slider for WooCommerce Pro < 3.5.3

Timeline

  • 2026-06-03: disclosed: Initial discovery and report by WPScan researcher
  • 2026-06-24: advisory: CVE published and NVD record created

References